A vulnerability, which was classified as critical, has been found in CodeIgniter up to 4.7.3. Affected by this issue is the function is_image/mime_in of the component Upload Validation. The manipulation leads to unrestricted upload.

This vulnerability is documented as CVE-2026-63223. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.