THREAT OPS › Threat News › [GHSA] GHSA-c9w5-rwh3-7pm9 (critical) — CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions
[GHSA] GHSA-c9w5-rwh3-7pm9 (critical) — CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions
GHSA-c9w5-rwh3-7pm9 Severity: critical CVE: CVE-2026-63221
CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions
### Impact A SQL injection vulnerability exists in the Query Builder's `deleteBatch()` method. When `deleteBatch()` is used together with `where()` conditions, the bound values from the `WHERE` clause are substituted directly into the generated SQ
Indicators of compromise
- CVE-2026-63221cve
Original source: https://github.com/advisories/GHSA-c9w5-rwh3-7pm9