CVE-2026-54182: CWE-20: Improper Input Validation in Laravel-Backpack CRUD
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::makeCurlRequest in src/Stats.php is reached from BackpackServiceProvider::boot() and constructs a shell command with a URL influenced by the HTTP Host header, which it passes to exec() without adequate shell neutralization. An unauthenticated attacker whose malformed Host value reaches PHP can inject operating-system commands when exec() and curl are available and the 1-in-100 random gate is reached. Repeated requests can reach the random gate. Successful exploitation executes commands as the web-server user, exposing environment secrets, files, and reachable services and permitting data modification or service disruption. Common reverse-proxy Host validation and hardened PHP configurations that disable exec() reduce reachability but do not correct the vulnerable construction. This issue is fixed in versions 4.1.70, 5.6.2, 6.8.13, and 7.0.36.
AI Analysis
Technical Summary
The vulnerability exists in Backpack\CRUD\Stats::makeCurlRequest, which is invoked from BackpackServiceProvider::boot(). It constructs a shell command using a URL influenced by the HTTP Host header without adequate shell neutralization before passing it to exec(). An attacker can supply a malformed Host header to inject OS commands when exec() and curl are available and a probabilistic 1-in-100 gate is triggered. Although reverse-proxy Host validation and hardened PHP configurations that disable exec() reduce the attack surface, they do not fully mitigate the issue. The flaw is fixed in versions 4.1.70, 5.6.2, 6.8.13, and 7.0.36.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary operating system commands as the web-server user. This can lead to disclosure of environment secrets, unauthorized file access, modification of data, and disruption of services. The vulnerability has a CVSS v3.1 score of 8.1 (high severity), indicating a significant impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade Laravel-Backpack CRUD to version 4.1.70, 5.6.2, 6.8.13, or 7.0.36 or later where this issue is fixed. Until patched, relying solely on reverse-proxy Host validation or disabling exec() in PHP configurations is insufficient to fully mitigate the risk. Applying the official fixes is the recommended remediation.
CVE-2026-54182: CWE-20: Improper Input Validation in Laravel-Backpack CRUD
Description
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::makeCurlRequest in src/Stats.php is reached from BackpackServiceProvider::boot() and constructs a shell command with a URL influenced by the HTTP Host header, which it passes to exec() without adequate shell neutralization. An unauthenticated attacker whose malformed Host value reaches PHP can inject operating-system commands when exec() and curl are available and the 1-in-100 random gate is reached. Repeated requests can reach the random gate. Successful exploitation executes commands as the web-server user, exposing environment secrets, files, and reachable services and permitting data modification or service disruption. Common reverse-proxy Host validation and hardened PHP configurations that disable exec() reduce reachability but do not correct the vulnerable construction. This issue is fixed in versions 4.1.70, 5.6.2, 6.8.13, and 7.0.36.
CVSS v3.1
Score 8.1high
Affected software
Laravel-Backpack
CRUD
pkg:github/laravel-backpack/CRUDRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in Backpack\CRUD\Stats::makeCurlRequest, which is invoked from BackpackServiceProvider::boot(). It constructs a shell command using a URL influenced by the HTTP Host header without adequate shell neutralization before passing it to exec(). An attacker can supply a malformed Host header to inject OS commands when exec() and curl are available and a probabilistic 1-in-100 gate is triggered. Although reverse-proxy Host validation and hardened PHP configurations that disable exec() reduce the attack surface, they do not fully mitigate the issue. The flaw is fixed in versions 4.1.70, 5.6.2, 6.8.13, and 7.0.36.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary operating system commands as the web-server user. This can lead to disclosure of environment secrets, unauthorized file access, modification of data, and disruption of services. The vulnerability has a CVSS v3.1 score of 8.1 (high severity), indicating a significant impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade Laravel-Backpack CRUD to version 4.1.70, 5.6.2, 6.8.13, or 7.0.36 or later where this issue is fixed. Until patched, relying solely on reverse-proxy Host validation or disabling exec() in PHP configurations is insufficient to fully mitigate the risk. Applying the official fixes is the recommended remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-11T21:46:52.382Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa836a955bf5e2cf5684396
Added to database: 09/14/2026, 18:02:17 UTC
Last enriched: 09/14/2026, 18:16:43 UTC
Last updated: 09/14/2026, 21:05:54 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.