GHSA-w9mx-xmg4-gc4r

    Dashboard / Vulnerabilities / GHSA-w9mx-xmg4-gc4r

    GHSA-w9mx-xmg4-gc4r

    Published: 9 Jul 2026Last Modified: 9 Jul 2026

    Summary: laravel-backup-restore has an OS Command Injection during database restore

    Details: ## Summary A crafted backup archive can trigger OS command injection during database restore. The restore workflow extracts a ZIP archive, enumerates files under `db-dumps`, converts the dump path to an absolute path, and passes that path into database import commands that are built as shell command strings. The dump filename is not shell-escaped before it is interpolated into commands such as: - `mysql ... < {dumpFile}` - `gunzip -c {dumpFile}` / `gunzip < {dumpFile}` - `psql ... < {dumpFile}` - `sqlite3 ... < {dumpFile}` Because `Illuminate\Support\Facades\Process::run(string)` uses Symfony `Process::fromShellCommandline()`, shell metacharacters in the dump filename are interpreted by `/bin/sh` on Unix-like systems or by the platform shell on Windows. ### Impact If an attacker can cause an operator or automation to restore a malicious backup archive, the attacker can execute arbitrary shell commands as the PHP/Laravel application user on the system performing the restore. This can lead to application compromise, database credential disclosure, tampering with restored data, and further lateral movement depending on deployment permissions. This is not about malicious SQL inside the dump. The command injection is carried in the ZIP entry filename under `db-dumps`, before the dump content is imported. ### Patches The vulnerability has been fixed in v1.9.4 of the package. ### Workarounds There is no configuration option that disables the vulnerable code path. Upgrading to the patched release is the only complete fix.

    Affected packages

    Package

    Name: wnx/laravel-backup-restore

    Purl: pkg:composer/wnx/laravel-backup-restore

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.9.4

    Affected versions

    v0.1.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-w9mx-xmg4-gc4r | CVE-DB