{"id":"CVE-2026-53932","title":"laravel-backup-restore restores database backups made with spatie/laravel-backup","summary":"laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-77","CWE-78"],"vendor":"stefanzweifel","product":"laravel-backup-restore","affected":["laravel-backup-restore < 1.9.4"],"patched":["wnx/laravel-backup-restore 1.9.4"],"published":"2026-09-04","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:41:33.140","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53932","references":[{"url":"https://github.com/stefanzweifel/laravel-backup-restore/commit/a73f6c3dfd57c5efbc46cce4e93ed033bedce8b0","label":"security-advisories@github.com"},{"url":"https://github.com/stefanzweifel/laravel-backup-restore/pull/116","label":"security-advisories@github.com"},{"url":"https://github.com/stefanzweifel/laravel-backup-restore/releases/tag/v1.9.4","label":"security-advisories@github.com"},{"url":"https://github.com/stefanzweifel/laravel-backup-restore/security/advisories/GHSA-w9mx-xmg4-gc4r","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-w9mx-xmg4-gc4r"}],"tags":["nvd","cve.org","ghsa","composer"],"epss":0.00907,"epssPercentile":0.57855,"aliases":["GHSA-w9mx-xmg4-gc4r"],"ecosystem":"composer","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-08T16:41:19.536896Z"},"ingestedAt":"2026-07-09T21:52:34.715Z","slug":"CVE-2026-53932","body":"## Overview\n\nlaravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-53932)\n\nAffected packages:\n\n- `wnx/laravel-backup-restore <= 1.9.3`\n\nPatched in:\n\n- `wnx/laravel-backup-restore 1.9.4`\n\nSource: https://github.com/advisories/GHSA-w9mx-xmg4-gc4r","depth":"twilight","depthScore":44,"depthScoreParts":{"impact":44,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}