CVE-2026-54177: CWE-434: Unrestricted Upload of File with Dangerous Type in Laravel-Backpack CRUD
A vulnerability in Laravel-Backpack CRUD allows authenticated administrators to upload files with dangerous types that can lead to remote code execution. This occurs in versions from 6.0.0 up to but not including 6.8.14, and from 7.0.0 up to but not including 7.0.38. The issue arises because certain upload methods do not internally reject server-executable file types when the public disk is web-accessible and the server executes files with those extensions. The vulnerability is fixed in versions 6.8.14 and 7.0.38.
AI Analysis
Technical Summary
Laravel-Backpack CRUD versions >=6.0.0 <6.8.14 and >=7.0.0 <7.0.38 contain a vulnerability (CWE-434) where the HasUploadFields methods uploadFileToDisk and uploadMultipleFilesToDisk, as well as the withFiles() path through FileNameGenerator, do not internally block server-executable file types. When used with an upload-enabled CRUD field lacking mimes: and mimetypes: validation, and when the public disk is web-accessible via php artisan storage:link with a web server and PHP-FPM configuration that executes stored extensions, an authenticated administrator can achieve remote code execution. The package-level restriction is intended as defense in depth and does not replace application-level validation. The issue is resolved in versions 6.8.14 and 7.0.38.
Potential Impact
An authenticated administrator can exploit this vulnerability to upload files with dangerous extensions that the web server may execute, leading to remote code execution. This compromises confidentiality, integrity, and availability of the affected system. The CVSS 3.1 score is 6.6 (medium severity) with network attack vector, high attack complexity, required privileges, no user interaction, unchanged scope, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade Laravel-Backpack CRUD to version 6.8.14 or later, or 7.0.38 or later, where this vulnerability is fixed. Additionally, ensure application-level upload validation is implemented using mimes: and mimetypes: rules to restrict dangerous file types. Avoid relying solely on package-level restrictions. Verify that the public disk is not web-accessible or that the web server and PHP-FPM configurations do not execute uploaded files with dangerous extensions.
CVE-2026-54177: CWE-434: Unrestricted Upload of File with Dangerous Type in Laravel-Backpack CRUD
Description
A vulnerability in Laravel-Backpack CRUD allows authenticated administrators to upload files with dangerous types that can lead to remote code execution. This occurs in versions from 6.0.0 up to but not including 6.8.14, and from 7.0.0 up to but not including 7.0.38. The issue arises because certain upload methods do not internally reject server-executable file types when the public disk is web-accessible and the server executes files with those extensions. The vulnerability is fixed in versions 6.8.14 and 7.0.38.
CVSS v3.1
Score 6.6medium
Affected software
Laravel-Backpack
CRUD
pkg:github/laravel-backpack/CRUDRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Laravel-Backpack CRUD versions >=6.0.0 <6.8.14 and >=7.0.0 <7.0.38 contain a vulnerability (CWE-434) where the HasUploadFields methods uploadFileToDisk and uploadMultipleFilesToDisk, as well as the withFiles() path through FileNameGenerator, do not internally block server-executable file types. When used with an upload-enabled CRUD field lacking mimes: and mimetypes: validation, and when the public disk is web-accessible via php artisan storage:link with a web server and PHP-FPM configuration that executes stored extensions, an authenticated administrator can achieve remote code execution. The package-level restriction is intended as defense in depth and does not replace application-level validation. The issue is resolved in versions 6.8.14 and 7.0.38.
Potential Impact
An authenticated administrator can exploit this vulnerability to upload files with dangerous extensions that the web server may execute, leading to remote code execution. This compromises confidentiality, integrity, and availability of the affected system. The CVSS 3.1 score is 6.6 (medium severity) with network attack vector, high attack complexity, required privileges, no user interaction, unchanged scope, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade Laravel-Backpack CRUD to version 6.8.14 or later, or 7.0.38 or later, where this vulnerability is fixed. Additionally, ensure application-level upload validation is implemented using mimes: and mimetypes: rules to restrict dangerous file types. Avoid relying solely on package-level restrictions. Verify that the public disk is not web-accessible or that the web server and PHP-FPM configurations do not execute uploaded files with dangerous extensions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-11T21:46:52.381Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa836a955bf5e2cf5684391
Added to database: 09/14/2026, 18:02:17 UTC
Last enriched: 09/14/2026, 18:17:23 UTC
Last updated: 09/14/2026, 21:05:48 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.