PKSA-gr8y-xsj7-jw48 Security Advisory
-
[MEDIUM] Laravel Backpack CRUD: SingleBase64Image accepts any base64 payload behind a `data:image` prefix — SVG-with-script lands on the public disk
PKSA-gr8y-xsj7-jw48 CVE-2026-54179 GHSA-8hw4-7qjr-3wxg
Affected package: backpack/crud
Affected version: >=7.0.0,<7.0.38|>=6.0.0,<6.8.14
Reported by:
GitHub