CVE-2026-54178 | Laravel-Backpack CRUD up to 5.x/6.8.11/7.0.34 Upload HasUploadFields.php uploadMultipleFilesToDisk clear_[] path traversal
A vulnerability identified as problematic has been detected in Laravel-Backpack CRUD up to 5.x/6.8.11/7.0.34. Affected by this issue is the function HasUploadFields::uploadMultipleFilesToDisk of the file src/app/Models/Traits/HasUploadFields.php of the component Upload. This manipulation of the argument clear_[] causes path traversal.
This vulnerability is tracked as CVE-2026-54178. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.VulDB Recent EntriesRead More