{"id":"GHSA-c9w5-rwh3-7pm9","summary":"CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions","details":"### Impact\nA SQL injection vulnerability exists in the Query Builder's `deleteBatch()` method. When `deleteBatch()` is used together with `where()` conditions, the bound values from the `WHERE` clause are substituted directly into the generated SQL **with their escape flag ignored**, so they are never escaped or quoted. If an application passes user-controlled input to `where()` before calling `deleteBatch()`, that input is interpreted as SQL rather than as a value, allowing SQL injection.\n\nThis affects only the `deleteBatch()` code path. Regular `delete()` operations escape `where()` binds correctly.\n\n### Patches\nUpgrade to v4.7.4 or later.\n\n### Workarounds\nIf you cannot upgrade immediately:\n\n- Strictly validate and cast values (e.g. numeric IDs) before using them in conditions - though this does not fully protect string conditions.\n- Do not pass user-controlled input to `where()` when using `deleteBatch()`.\n- For user-controlled conditions, use a normal `delete()` with Query Builder binds instead of `deleteBatch(`).\n- Where possible, express required matching values through the batch data and `onConstraint()` rather than as separate user-controlled `where()` clauses.","aliases":["CVE-2026-63221"],"modified":"2026-08-07T18:30:07.051255222Z","published":"2026-08-07T18:22:59Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-08-07T18:22:59Z","nvd_published_at":"2026-07-31T06:16:31Z","cwe_ids":["CWE-89"]},"references":[{"type":"WEB","url":"https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-c9w5-rwh3-7pm9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63221"},{"type":"WEB","url":"https://github.com/codeigniter4/CodeIgniter4/commit/f5e463b9a3e986389ce285963e51a7f1fab6559f"},{"type":"PACKAGE","url":"https://github.com/codeigniter4/CodeIgniter4"},{"type":"WEB","url":"https://github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.4"}],"affected":[{"package":{"name":"codeigniter4/framework","ecosystem":"Packagist","purl":"pkg:composer/codeigniter4/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.3.0"},{"fixed":"4.7.4"}]}],"versions":["v4.3.0","v4.3.1","v4.3.2","v4.3.3","v4.3.4","v4.3.5","v4.3.6","v4.3.7","v4.3.8","v4.4.0","v4.4.1","v4.4.2","v4.4.3","v4.4.4","v4.4.5","v4.4.6","v4.4.7","v4.4.8","v4.5.0","v4.5.1","v4.5.2","v4.5.3","v4.5.4","v4.5.5","v4.5.6","v4.5.7","v4.5.8","v4.6.0","v4.6.1","v4.6.2","v4.6.3","v4.6.4","v4.6.5","v4.7.0","v4.7.1","v4.7.2","v4.7.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-c9w5-rwh3-7pm9/GHSA-c9w5-rwh3-7pm9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"}]}