Skip to content

Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)

High severity GitHub Reviewed Published Jun 15, 2026 in Laravel-Backpack/CRUD • Updated Aug 20, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts