Warning: Command Injection Vulnerability in CodeIgniter4 ImageMagick Handler, Patch Immediately!
ID: 3c2dcd45-9531-5e6a-a965-7e66f497811d
STIX ID: report--3c2dcd45-9531-5e6a-a965-7e66f497811d
CodeIgniter4 has a critical command‑injection/RCE vulnerability (CVE-2025-54418, CVSS 9.8) in its ImageManipulation component when the non-default ImageMagick handler is used; attackers can execute OS commands via unsanitized user-controlled filenames during uploads or via unvalidated text overlay inputs. The advisory recommends urgent patching, applying listed mitigations if immediate patching is not possible, and increasing monitoring and detection; no evidence of in‑the‑wild exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
