Description
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, src/resources/views/crud/columns/color.blade.php inverts the escaped and raw rendering branches controlled by $column['escaped'], which defaults to true, causing $column['text'] to be rendered unescaped by default. An attacker who can store an unsanitized value in a color column can execute script in the browser of a user who views the CRUD list, including an administrator, with access to the victim's session-backed application capabilities. Exploitation requires write access to the stored color value and a victim viewing the list. This issue is fixed in versions 6.8.14 and 7.0.38.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS) in Backpack‑CRUD color column
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from Backpack‑CRUD’s color column template, which mistakenly renders raw content because the $column['escaped'] flag logic is inverted. The affected template is used in versions from 6.0.0 through 6.8.14 and 7.0.38. A malicious actor who can write into this column can embed JavaScript that will execute in any user’s browser that opens the CRUD list, including administrators. The flaw is limited to client‑side execution; it does not allow server‑side code execution or arbitrary file uploads, but it enables stealth attacks such as cookie theft or unauthorized actions within the application.

Affected Systems

Affected products are Laravel‑Backpack:CRUD, versions released between 6.0.0 and just before 6.8.14, and also all releases leading up to 7.0.38. Users running any version of Backpack‑CRUD older than 6.0.38 should be aware that the color column could render unescaped content.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score of < 1% shows a very low but nonzero likelihood of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have write access to the color page; once an untrusted script is stored, any user who opens the list will execute it, potentially compromising session data or performing actions on behalf of the victim within the application.

Generated by OpenCVE AI on September 20, 2026 at 22:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Laravel‑Backpack:CRUD to at least version 6.8.14 or 7.0.38, which contains the patch for this flaw.
  • Prior to upgrading, sanitize or delete any existing color column entries that contain untrusted content, ensuring that only safe color codes or escaped text remain in the database.
  • Implement input validation for the color field in the application logic so that only legitimate hex color values or a predefined set of safe strings are accepted, preventing future injection of malicious JavaScript.

Generated by OpenCVE AI on September 20, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mmg4-322v-6jvc Laravel Backpack CRUD: Stored XSS in the color column — the `@if($column['escaped'])` branches are inverted
History

Tue, 15 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Laravel-backpack
Laravel-backpack crud
Vendors & Products Laravel-backpack
Laravel-backpack crud

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, src/resources/views/crud/columns/color.blade.php inverts the escaped and raw rendering branches controlled by $column['escaped'], which defaults to true, causing $column['text'] to be rendered unescaped by default. An attacker who can store an unsanitized value in a color column can execute script in the browser of a user who views the CRUD list, including an administrator, with access to the victim's session-backed application capabilities. Exploitation requires write access to the stored color value and a victim viewing the list. This issue is fixed in versions 6.8.14 and 7.0.38.
Title backpack/crud: Stored XSS in the color column — the `@if($column['escaped'])` branches are inverted
Weaknesses CWE-1023
CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Laravel-backpack Crud
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:05:31.606Z

Reserved: 2026-06-11T21:46:52.382Z

Link: CVE-2026-54181

cve-icon Vulnrichment

Updated: 2026-09-14T19:20:43.379Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:53.223

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:00:07Z

Weaknesses
  • CWE-1023

    Incomplete Comparison with Missing Factors

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')