CVE-2026-54181
Last modified
CVE-2026-54181 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, src/resources/views/crud/columns/color.blade.php inverts the escaped and raw rendering branches controlled by $column['escaped'], which defaults to true, causing $column['text'] to be rendered unescaped by default.
Description
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, src/resources/views/crud/columns/color.blade.php inverts the escaped and raw rendering branches controlled by $column['escaped'], which defaults to true, causing $column['text'] to be rendered unescaped by default. An attacker who can store an unsanitized value in a color column can execute script in the browser of a user who views the CRUD list, including an administrator, with access to the victim's session-backed application capabilities. Exploitation requires write access to the stored color value and a victim viewing the list. This issue is fixed in versions 6.8.14 and 7.0.38.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Laravel-Backpack | CRUD | >= 6.0.0, < 6.8.14; >= 7.0.0, < 7.0.38 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-54181?
How severe is CVE-2026-54181?
How do I fix CVE-2026-54181?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54176backpack/crud provides Create, Read, Update & Delete (CRUD) …6.5
- CVE-2026-54177backpack/crud provides Create, Read, Update & Delete (CRUD) …6.6
- CVE-2026-54178backpack/crud provides Create, Read, Update & Delete (CRUD) …8.1
- CVE-2026-54179backpack/crud provides Create, Read, Update & Delete (CRUD) …4.4
- CVE-2026-5418A vulnerability was identified in appsmithorg appsmith up to…7.3
- CVE-2026-54180backpack/crud provides Create, Read, Update & Delete (CRUD) …7.6
- CVE-2026-54182backpack/crud provides Create, Read, Update & Delete (CRUD) …8.1
- CVE-2026-54183Apache Airflow's secrets masker hides values stored under se…4.3
- CVE-2026-54184Unauthenticated Insecure Direct Object References (IDOR) in …8.2
- CVE-2026-54185Subscriber SQL Injection in Cornerstone < 7.8.8 versions.8.5
- CVE-2026-54186Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions…9.3
- CVE-2026-54187Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versi…9.3
Are you affected by CVE-2026-54181?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
