{"id":"GHSA-2pcj-76hj-xqhm","summary":"CodeIgniter arbitrary code execution","details":"system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email-\u003efrom field to insert sendmail command-line arguments.","aliases":["CVE-2016-10131"],"modified":"2026-09-10T03:49:18.807741446Z","published":"2022-05-17T02:55:21Z","database_specific":{"nvd_published_at":"2017-01-12T06:59:00Z","cwe_ids":["CWE-74"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-04-24T17:49:18Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10131"},{"type":"WEB","url":"https://github.com/bcit-ci/CodeIgniter/issues/4844"},{"type":"WEB","url":"https://github.com/bcit-ci/CodeIgniter/issues/4963"},{"type":"WEB","url":"https://github.com/bcit-ci/CodeIgniter/commit/8db01f13809a92bac7bc95b02893175d7654d627"},{"type":"PACKAGE","url":"https://github.com/codeigniter4/framework"},{"type":"WEB","url":"https://www.codeigniter.com/userguide3/changelog.html#bug-fixes-for-3-1-3"},{"type":"WEB","url":"http://www.securityfocus.com/bid/96851"}],"affected":[{"package":{"name":"bcit-ci/codeigniter","ecosystem":"Packagist","purl":"pkg:composer/bcit-ci/codeigniter"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3"}]}],"versions":["3.0.0","3.0.1","3.0.1rc","3.0.1rc2","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0rc","3.0rc2","3.0rc3","3.1.0","3.1.1","3.1.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-2pcj-76hj-xqhm/GHSA-2pcj-76hj-xqhm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}