{"id":"CVE-2026-54182","aliases":["GHSA-mrc5-3mm3-45c5"],"url":"https://o3.security/vulnerability/CVE-2026-54182","summary":"backpack/crud: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)","details":"## Summary\n\n`Backpack\\CRUD\\Stats::makeCurlRequest` builds a shell command using unescaped input that originates from the HTTP `Host` header, then passes it to `exec()`. A specially crafted Host header can break out of the shell argument and cause the server to execute arbitrary OS commands as the web user.\n\nThe vulnerable code path is reached from `BackpackServiceProvider::boot()` on every HTTP request in production when `exec()` and `curl` are available. A 1-in-100 random gate is the only guard — an attacker can reliably trigger it by retrying.\n\n## Severity\n\n**High — CVSS 8.1**  \n`CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H`\n\nAttack Complexity is rated **High** because default nginx and Apache configurations typically strip or reject malformed Host headers before they reach PHP, and `exec()` is often disabled for web processes in hardened environments. Both mitigations must be absent for exploitation.\n\n## Impact\n\nA successful exploit yields OS command execution as the web server user (`www-data`, `nginx`, etc.), giving an unauthenticated attacker access to environment secrets (APP_KEY, database credentials, API keys in `.env`), the filesystem, and any service the server can reach.\n\n## Fix\n\n`makeCurlRequest` was replaced with the Guzzle-based path already present in the codebase, eliminating the shell-command construction entirely. **Upgrade to a patched release immediately.**\n\n## Affected versions\n\n| Branch | Vulnerable range | First safe version |\n|--------|-----------------|-------------------|\n| 4.1.x  | `< 4.1.70`      | 4.1.70            |\n| 5.x    | `< 5.6.2`       | 5.6.2             |\n| 6.x    | `< 6.8.13`      | 6.8.13            |\n| 7.x    | `< 7.0.36`      | 7.0.36            |\n\n## Credits\n\nReported by Vishal Shukla ([@shukla304](https://github.com/shukla304)) via sechub.dev AI Agent.","published":"2026-09-14T17:48:21.509Z","modified":"2026-10-02T03:31:09.252142777Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"backpack/crud","fixedVersion":"4.1.72"},{"ecosystem":"Packagist","name":"backpack/crud","fixedVersion":"5.6.2"},{"ecosystem":"Packagist","name":"backpack/crud","fixedVersion":"6.8.13"},{"ecosystem":"Packagist","name":"backpack/crud","fixedVersion":"7.0.36"}],"fix":{"url":"https://github.com/Laravel-Backpack/CRUD/commit/0f2faafc22a15d77c14370f163d8f739f933c28c","label":"Laravel-Backpack/CRUD@0f2faaf"},"references":[{"type":"WEB","url":"https://github.com/Laravel-Backpack/CRUD/releases/tag/4.1.72"},{"type":"WEB","url":"https://github.com/Laravel-Backpack/CRUD/releases/tag/5.6.2"},{"type":"WEB","url":"https://github.com/Laravel-Backpack/CRUD/releases/tag/6.8.13"},{"type":"WEB","url":"https://github.com/Laravel-Backpack/CRUD/releases/tag/7.0.36"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54182.json"},{"type":"ADVISORY","url":"https://github.com/Laravel-Backpack/CRUD/security/advisories/GHSA-mrc5-3mm3-45c5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54182"},{"type":"FIX","url":"https://github.com/Laravel-Backpack/CRUD/commit/0f2faafc22a15d77c14370f163d8f739f933c28c"},{"type":"FIX","url":"https://github.com/Laravel-Backpack/CRUD/commit/1476a3769d94a410a2d2e9576deb522e84002f2a"},{"type":"FIX","url":"https://github.com/Laravel-Backpack/CRUD/commit/282ba2a0b88749fb1888b3836678ba462d7023f0"},{"type":"FIX","url":"https://github.com/Laravel-Backpack/CRUD/commit/471935e296b1be1a7216fdf10c8823e1f512f601"},{"type":"FIX","url":"https://github.com/Laravel-Backpack/CRUD/pull/6012"},{"type":"PACKAGE","url":"https://github.com/Laravel-Backpack/CRUD"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T03:31:09.252142777Z"}}