{"id":"CVE-2026-54182","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-54182","summary":"Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)","details":"## Summary\n\n`Backpack\\CRUD\\Stats::makeCurlRequest` builds a shell command using unescaped input that originates from the HTTP `Host` header, then passes it to `exec()`. A specially crafted Host header can break out of the shell argument and cause the server to execute arbitrary OS commands as the web user.\n\nThe vulnerable code path is reached from `BackpackServiceProvider::boot()` on every HTTP request in production when `exec()` and `curl` are available. A 1-in-100 random gate is the only guard — an attacker can reliably trigger it by retrying.\n\n## Severity\n\n**High — CVSS 8.1**  \n`CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H`\n\nAttack Complexity is rated **High** because default nginx and Apache configurations typically strip or reject malformed Host headers before they reach PHP, and `exec()` is often disabled for web processes in hardened environments. Both mitigations must be absent for exploitation.\n\n## Impact\n\nA successful exploit yields OS command execution as the web server user (`www-data`, `nginx`, etc.), giving an unauthenticated attacker access to environment secrets (APP_KEY, database credentials, API keys in `.env`), the filesystem, and any service the server can reach.\n\n## Fix\n\n`makeCurlRequest` was replaced with the Guzzle-based path already present in the codebase, eliminating the shell-command construction entirely. **Upgrade to a patched release immediately.**\n\n## Affected versions\n\n| Branch | Vulnerable range | First safe version |\n|--------|-----------------|-------------------|\n| 4.1.x  | `< 4.1.70`      | 4.1.70            |\n| 5.x    | `< 5.6.2`       | 5.6.2             |\n| 6.x    | `< 6.8.13`      | 6.8.13            |\n| 7.x    | `< 7.0.36`      | 7.0.36            |\n\n## Credits\n\nReported by Vishal Shukla ([@shukla304](https://github.com/shukla304)) via sechub.dev AI Agent.","published":"2026-08-20T18:38:55Z","modified":"2026-08-20T18:45:13.567340579Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"backpack/crud","fixedVersion":"4.1.72"},{"ecosystem":"Packagist","name":"backpack/crud","fixedVersion":"5.6.2"},{"ecosystem":"Packagist","name":"backpack/crud","fixedVersion":"6.8.13"},{"ecosystem":"Packagist","name":"backpack/crud","fixedVersion":"7.0.36"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Laravel-Backpack/CRUD/security/advisories/GHSA-mrc5-3mm3-45c5"},{"type":"PACKAGE","url":"https://github.com/Laravel-Backpack/CRUD"},{"type":"WEB","url":"https://github.com/Laravel-Backpack/CRUD/releases/tag/4.1.72"},{"type":"WEB","url":"https://github.com/Laravel-Backpack/CRUD/releases/tag/5.6.2"},{"type":"WEB","url":"https://github.com/Laravel-Backpack/CRUD/releases/tag/6.8.13"},{"type":"WEB","url":"https://github.com/Laravel-Backpack/CRUD/releases/tag/7.0.36"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T18:45:13.567340579Z"}}