Command Injection Vulnerability in CodeIgniter Framework Affecting Image Processing
CVE-2025-54418
Key Information:
- Vendor
Codeigniter4
- Status
- Vendor
- CVE Published:
- 28 July 2025
Badges
What is CVE-2025-54418?
CVE-2025-54418 is a command injection vulnerability found in the CodeIgniter framework, specifically versions prior to 4.6.2, which is widely utilized for developing PHP-based web applications. This vulnerability affects applications that use the ImageMagick library for image processing, where user-controlled filenames or text content can lead to unintended command execution. Attackers can exploit this flaw by uploading files with malicious filenames containing shell metacharacters, which are executed during image processing, or by providing harmful text inputs that the server subsequently executes. Such vulnerabilities can significantly undermine the integrity of web applications that handle image uploads or allow for user-generated content, exposing organizations to substantial security risks.
Potential impact of CVE-2025-54418
-
Remote Code Execution: Attackers can leverage this vulnerability to execute arbitrary commands on the server, potentially gaining unauthorized access to system resources and sensitive data, thereby compromising the overall security of the application.
-
Data Breaches: The exploitation of this vulnerability may lead to data leaks or unauthorized modification of sensitive information stored on the affected systems, resulting in potential regulatory penalties and loss of customer trust.
-
Deployment of Malicious Payloads: Once control is gained through this vulnerability, malicious actors could deploy various forms of malware, including ransomware, facilitating further attacks and significantly disrupting business operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CodeIgniter4 < 4.6.2
News Articles
Critical CodeIgniter4 Vulnerability CVE-2025-54418
A severe CodeIgniter4 flaw (CVE-2025-54418) allows file upload attacks. Patch now or follow mitigations to protect apps from command injection threats.
Critical CodeIgniter4 Vulnerability CVE-2025-54418
A severe CodeIgniter4 flaw (CVE-2025-54418) allows file upload attacks. Patch now or follow mitigations to protect apps from command injection threats.
Critical CodeIgniter4 Vulnerability CVE-2025-54418
A severe CodeIgniter4 flaw (CVE-2025-54418) allows file upload attacks. Patch now or follow mitigations to protect apps from command injection threats.
References
CVSS V3.1
Timeline
- πΎ
Exploit known to exist
- π°
First article discovered by GBHackers News
Vulnerability published
Vulnerability Reserved
