Skip to main content

CVE-2026-54182: CWE-20: Improper Input Validation in Laravel-Backpack CRUD

0
High
VulnerabilityCVE-2026-54182cvecve-2026-54182cwe-20cwe-78cwe-116
Published: 09/14/2026 (09/14/2026, 17:48:21 UTC)
Source: CVE Database V5
Vendor/Project: Laravel-Backpack
Product: CRUD

Description

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::makeCurlRequest in src/Stats.php is reached from BackpackServiceProvider::boot() and constructs a shell command with a URL influenced by the HTTP Host header, which it passes to exec() without adequate shell neutralization. An unauthenticated attacker whose malformed Host value reaches PHP can inject operating-system commands when exec() and curl are available and the 1-in-100 random gate is reached. Repeated requests can reach the random gate. Successful exploitation executes commands as the web-server user, exposing environment secrets, files, and reachable services and permitting data modification or service disruption. Common reverse-proxy Host validation and hardened PHP configurations that disable exec() reduce reachability but do not correct the vulnerable construction. This issue is fixed in versions 4.1.70, 5.6.2, 6.8.13, and 7.0.36.

CVSS v3.1

Score 8.1high

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected software

Laravel-Backpack

CRUD

Affected versions
<4.1.70>=5.0.0 <5.6.2>=6.0.0 <6.8.13>=7.0.0 <7.0.36
GitHub Actionsmore threats →ai
laravel-backpack/CRUD
pkg:github/laravel-backpack/CRUD
Affected versions
<4.1.70>=5.0.0 <5.6.2>=6.0.0 <6.8.13>=7.0.0 <7.0.36

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/14/2026, 18:16:43 UTC

Technical Analysis

The vulnerability exists in Backpack\CRUD\Stats::makeCurlRequest, which is invoked from BackpackServiceProvider::boot(). It constructs a shell command using a URL influenced by the HTTP Host header without adequate shell neutralization before passing it to exec(). An attacker can supply a malformed Host header to inject OS commands when exec() and curl are available and a probabilistic 1-in-100 gate is triggered. Although reverse-proxy Host validation and hardened PHP configurations that disable exec() reduce the attack surface, they do not fully mitigate the issue. The flaw is fixed in versions 4.1.70, 5.6.2, 6.8.13, and 7.0.36.

Potential Impact

Successful exploitation allows unauthenticated remote attackers to execute arbitrary operating system commands as the web-server user. This can lead to disclosure of environment secrets, unauthorized file access, modification of data, and disruption of services. The vulnerability has a CVSS v3.1 score of 8.1 (high severity), indicating a significant impact on confidentiality, integrity, and availability.

Mitigation Recommendations

Upgrade Laravel-Backpack CRUD to version 4.1.70, 5.6.2, 6.8.13, or 7.0.36 or later where this issue is fixed. Until patched, relying solely on reverse-proxy Host validation or disabling exec() in PHP configurations is insufficient to fully mitigate the risk. Applying the official fixes is the recommended remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-11T21:46:52.382Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aa836a955bf5e2cf5684396

Added to database: 09/14/2026, 18:02:17 UTC

Last enriched: 09/14/2026, 18:16:43 UTC

Last updated: 09/14/2026, 21:05:54 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses