GHSA-vgmv-8xjc-6rch

Suggest an improvement
Source
https://github.com/advisories/GHSA-vgmv-8xjc-6rch
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-vgmv-8xjc-6rch/GHSA-vgmv-8xjc-6rch.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vgmv-8xjc-6rch
Aliases
Published
2026-08-20T18:38:46Z
Modified
2026-08-20T18:48:08Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L CVSS Calculator
Summary
Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)
Details

Summary

Backpack CRUD's list and read operations correctly apply any query scopes registered via addClause() / addBaseClause() (e.g. tenant isolation, user ownership). However, the Update, Delete, and Reorder operations bypassed these scopes, fetching records directly from the unscoped model query.

An authenticated user who knows or can guess a record's primary key could therefore update, delete, or reorder records that should be invisible to them — a classic IDOR on write paths.

Applications that rely on addBaseClause for row-level access control (multi-tenancy, per-user data isolation) are affected.

Impact

Any Backpack CRUD panel that uses addBaseClause or addClause to restrict which rows a user may access is affected on its write operations. An authenticated low-privilege user can modify or delete records belonging to other tenants / users.

Patches

Apply the fixed release for your major version:

  • v6: upgrade to 6.8.14 or later
  • v7: upgrade to 7.0.38 or later

The fix ensures Update, Delete, and Reorder all resolve records through the same scoped query used by the read side.

Workarounds

If you cannot upgrade immediately, add explicit Gate / Policy checks in your CrudController's update(), destroy(), and reorder() methods to verify the authenticated user is permitted to act on the resolved record.

Credits

Reported by Vishal Shukla (@shukla304).

Database specific
{
    "cwe_ids":  [
        "CWE-639",
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-20T18:38:46Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Packagist / backpack/crud

Package

Name
backpack/crud
Purl
pkg:composer/backpack/crud

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.8.14

Affected versions

6.*
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
6.1.9
6.1.10
6.1.11
6.1.12
6.1.13
6.1.14
6.1.15
6.1.16
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.3.0
6.3.1
6.3.2
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.5.2
6.5.3
6.5.4
6.5.5
6.6.0
6.6.1
6.6.2
6.6.3
6.6.4
6.6.5
6.6.6
6.7.0
6.7.1
6.7.2
6.7.3
6.7.4
6.7.5
6.7.6
6.7.7
6.7.8
6.7.9
6.7.10
6.7.11
6.7.12
6.7.13
6.7.14
6.7.15
6.7.16
6.7.17
6.7.18
6.7.19
6.7.20
6.7.21
6.7.22
6.7.23
6.7.24
6.7.25
6.7.26
6.7.27
6.7.28
6.7.29
6.7.30
6.7.31
6.7.32
6.7.33
6.7.34
6.7.35
6.7.36
6.7.37
6.7.38
6.7.39
6.7.40
6.7.41
6.7.42
6.7.43
6.7.44
6.7.45
6.7.46
6.7.47
6.7.48
6.7.49
6.7.50
6.7.51
6.7.52
6.7.53
6.7.54
6.7.55
6.7.56
6.8.0
6.8.1
6.8.2
6.8.3
6.8.4
6.8.5
6.8.6
6.8.7
6.8.8
6.8.9
6.8.10
6.8.11
6.8.12
6.8.13

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-vgmv-8xjc-6rch/GHSA-vgmv-8xjc-6rch.json"

Packagist / backpack/crud

Package

Name
backpack/crud
Purl
pkg:composer/backpack/crud

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.0.38

Affected versions

7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.0.9
7.0.10
7.0.11
7.0.12
7.0.13
7.0.14
7.0.15
7.0.16
7.0.17
7.0.18
7.0.19
7.0.20
7.0.21
7.0.22
7.0.23
7.0.24
7.0.25
7.0.26
7.0.27
7.0.28
7.0.29
7.0.30
7.0.31
7.0.32
7.0.33
7.0.34
7.0.35
7.0.36
7.0.37

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-vgmv-8xjc-6rch/GHSA-vgmv-8xjc-6rch.json"