backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::makeCurlRequest in src/Stats.php is reached from BackpackServiceProvider::boot() and constructs a shell command with a URL influenced by the HTTP Host header, which it passes to exec() without adequate shell neutralization. An unauthenticated attacker whose malformed Host value reaches PHP can inject operating-system commands when exec() and curl are available and the 1-in-100 random gate is reached. Repeated requests can reach the random gate. Successful exploitation executes commands as the web-server user, exposing environment secrets, files, and reachable services and permitting data modification or service disruption. Common reverse-proxy Host validation and hardened PHP configurations that disable exec() reduce reachability but do not correct the vulnerable construction. This issue is fixed in versions 4.1.70, 5.6.2, 6.8.13, and 7.0.36.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-116",
"CWE-20",
"CWE-78"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54182.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.1.70"
},
{
"introduced": "5.0.0"
},
{
"fixed": "5.6.2"
},
{
"introduced": "6.0.0"
},
{
"fixed": "6.8.13"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.0.36"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}