Command Injection Vulnerability in CodeIgniter Framework Affecting Image Processing
CVE-2025-54418

9.8CRITICAL

Key Information:

Vendor
CVE Published:
28 July 2025

Badges

πŸ“ˆ Score: 649πŸ‘Ύ Exploit ExistsπŸ“° News Worthy

What is CVE-2025-54418?

CVE-2025-54418 is a command injection vulnerability found in the CodeIgniter framework, specifically versions prior to 4.6.2, which is widely utilized for developing PHP-based web applications. This vulnerability affects applications that use the ImageMagick library for image processing, where user-controlled filenames or text content can lead to unintended command execution. Attackers can exploit this flaw by uploading files with malicious filenames containing shell metacharacters, which are executed during image processing, or by providing harmful text inputs that the server subsequently executes. Such vulnerabilities can significantly undermine the integrity of web applications that handle image uploads or allow for user-generated content, exposing organizations to substantial security risks.

Potential impact of CVE-2025-54418

  1. Remote Code Execution: Attackers can leverage this vulnerability to execute arbitrary commands on the server, potentially gaining unauthorized access to system resources and sensitive data, thereby compromising the overall security of the application.

  2. Data Breaches: The exploitation of this vulnerability may lead to data leaks or unauthorized modification of sensitive information stored on the affected systems, resulting in potential regulatory penalties and loss of customer trust.

  3. Deployment of Malicious Payloads: Once control is gained through this vulnerability, malicious actors could deploy various forms of malware, including ransomware, facilitating further attacks and significantly disrupting business operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CodeIgniter4 < 4.6.2

News Articles

Critical CodeIgniter4 Vulnerability CVE-2025-54418

A severe CodeIgniter4 flaw (CVE-2025-54418) allows file upload attacks. Patch now or follow mitigations to protect apps from command injection threats.

Critical CodeIgniter4 Vulnerability CVE-2025-54418

A severe CodeIgniter4 flaw (CVE-2025-54418) allows file upload attacks. Patch now or follow mitigations to protect apps from command injection threats.

Critical CodeIgniter4 Vulnerability CVE-2025-54418

A severe CodeIgniter4 flaw (CVE-2025-54418) allows file upload attacks. Patch now or follow mitigations to protect apps from command injection threats.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by GBHackers News

  • Vulnerability published

  • Vulnerability Reserved

.