VYPR

Backpack CRUD

by Backpack

CVEs (1)

  • CVE-2026-54177Aug 20, 2026
    risk 0.00cvss epss

    ## Summary `HasUploadFields` (used via `CrudTrait` on Backpack-managed models) and the `withFiles()` uploader preserve the client-supplied file extension without validation. On installations using a `public` disk with `php artisan storage:link`, this allows an authenticated…