PKSA-ykyc-889h-7jxf Security Advisory
-
[HIGH] CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
PKSA-ykyc-889h-7jxf CVE-2026-63222 GHSA-hhmc-q9hp-r662
Affected package: codeigniter4/framework
Affected version: <4.7.4
Reported by:
GitHub