• Sources: advisory, advisory, release
  • Summary: CodeIgniter 4.7.4 fixes two GitHub-reviewed critical advisories that entered the GitHub Advisory Database on 2026-08-07. GHSA-c9w5-rwh3-7pm9 is CVE-2026-63221, CWE-89, scored CVSS 9.4, and affects versions from 4.3.0 up to but excluding 4.7.4. It is a SQL injection in the Query Builder deleteBatch() method used together with where() conditions, and the advisory states that regular delete() operations escape where() binds correctly. That advisory was published in codeigniter4/CodeIgniter4 on 2026-07-07 and by NVD on 2026-07-31, so what is new on 2026-08-07 is the advisory database entry rather than the release. GHSA-mmj4-63m4-r6h5 is a file-upload extension bypass, and its affected version range is not established here because the advisory was not read in this run.
  • Why it matters: The injection path is narrow enough that a team can triage its own code for deleteBatch() with where(), and every published workaround costs an application change, so upgrading to 4.7.4 is the cheaper remediation.

send feedback on this story