{"id":"CVE-2026-53932","summary":"wnx/laravel-backup-restore: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') and Improper Neutralization of Special Elements used in a Command ('Command Injection')","details":"laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.","aliases":["GHSA-w9mx-xmg4-gc4r"],"modified":"2026-09-06T03:46:14.698635339Z","published":"2026-09-04T19:48:52.844Z","database_specific":{"cwe_ids":["CWE-77","CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53932.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/stefanzweifel/laravel-backup-restore/releases/tag/v1.9.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53932.json"},{"type":"ADVISORY","url":"https://github.com/stefanzweifel/laravel-backup-restore/security/advisories/GHSA-w9mx-xmg4-gc4r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53932"},{"type":"FIX","url":"https://github.com/stefanzweifel/laravel-backup-restore/commit/a73f6c3dfd57c5efbc46cce4e93ed033bedce8b0"},{"type":"FIX","url":"https://github.com/stefanzweifel/laravel-backup-restore/pull/116"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/stefanzweifel/laravel-backup-restore","events":[{"introduced":"0"},{"fixed":"a73f6c3dfd57c5efbc46cce4e93ed033bedce8b0"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.9.4"}]}}],"versions":["v1.9.3","v1.9.2","v1.9.1","v1.9.0","v1.8.0","v1.7.0","v1.6.2","v1.6.1","v1.6.0","v1.5.2","v1.5.1","v1.5.0","v1.4.2","v1.4.1","v1.4.0","v1.3.2","v1.3.1","v1.3.0","v1.2.0","v1.1.5","v1.1.4","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.2","v1.0.1","v1.0.0","v0.3.1","v0.3.0","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53932.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}