Description
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::makeCurlRequest in src/Stats.php is reached from BackpackServiceProvider::boot() and constructs a shell command with a URL influenced by the HTTP Host header, which it passes to exec() without adequate shell neutralization. An unauthenticated attacker whose malformed Host value reaches PHP can inject operating-system commands when exec() and curl are available and the 1-in-100 random gate is reached. Repeated requests can reach the random gate. Successful exploitation executes commands as the web-server user, exposing environment secrets, files, and reachable services and permitting data modification or service disruption. Common reverse-proxy Host validation and hardened PHP configurations that disable exec() reduce reachability but do not correct the vulnerable construction. This issue is fixed in versions 4.1.70, 5.6.2, 6.8.13, and 7.0.36.
Published: 2026-09-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution via OS injection
Action: Immediate Patch
AI Analysis

Impact

Backpack‑CRUD, a Laravel package suite for admin panels, has a flaw in Stats::makeCurlRequest. The method concatenates an attacker‑controlled HTTP Host header into a shell command that is passed to exec() without proper sanitization. When exec() and curl are available, an unauthenticated attacker can trigger a 1‑in‑100 “random gate” by sending repeated requests. If the gate opens, arbitrary OS commands run as the web‑server user, exposing environment secrets, files, and enabling data modification or service disruption.

Affected Systems

All releases of Laravel‑Backpack:CRUD before 4.1.70, 5.6.2, 6.8.13, and 7.0.36 are affected. These are the versions that have not yet applied the vendor‑supplied patch.

Risk and Exploitability

The CVSS score of 8.1 classifies the issue as High severity. The EPSS score of less than 1% indicates a low probability of exploitation, but the vulnerability is not in CISA’s KEV catalog. A remote attacker can exploit the flaw over the network with no authentication by sending crafted Host headers. Repeated requests allow the attacker to hit the random gate, executing arbitrary OS commands as the web‑server user, which can lead to credential theft, data tampering, or denial of service.

Generated by OpenCVE AI on September 20, 2026 at 22:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Backpack‑CRUD to a patched release (4.1.70, 5.6.2, 6.8.13, or 7.0.36).
  • Disable or restrict PHP’s exec() function via php.ini disable_functions if exec() is not required for other features.
  • Validate or sanitize the HTTP Host header so that only legitimate values reach Stats::makeCurlRequest, or configure the web server to strip the header for internal requests.

Generated by OpenCVE AI on September 20, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mrc5-3mm3-45c5 Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)
History

Tue, 15 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Laravel-backpack
Laravel-backpack crud
Vendors & Products Laravel-backpack
Laravel-backpack crud

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::makeCurlRequest in src/Stats.php is reached from BackpackServiceProvider::boot() and constructs a shell command with a URL influenced by the HTTP Host header, which it passes to exec() without adequate shell neutralization. An unauthenticated attacker whose malformed Host value reaches PHP can inject operating-system commands when exec() and curl are available and the 1-in-100 random gate is reached. Repeated requests can reach the random gate. Successful exploitation executes commands as the web-server user, exposing environment secrets, files, and reachable services and permitting data modification or service disruption. Common reverse-proxy Host validation and hardened PHP configurations that disable exec() reduce reachability but do not correct the vulnerable construction. This issue is fixed in versions 4.1.70, 5.6.2, 6.8.13, and 7.0.36.
Title backpack/crud: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)
Weaknesses CWE-116
CWE-20
CWE-78
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Laravel-backpack Crud
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:17:49.976Z

Reserved: 2026-06-11T21:46:52.382Z

Link: CVE-2026-54182

cve-icon Vulnrichment

Updated: 2026-09-14T18:17:44.087Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:53.380

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-54182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:00:07Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output

  • CWE-20

    Improper Input Validation

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')