A vulnerability, which was classified as critical, was found in CodeIgniter up to 4.7.3. This affects the function
UploadedFile::move. The manipulation results in path traversal.
This vulnerability is reported as CVE-2026-63222. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.