CVE-2026-53932
laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.
- Published Sep 4, 2026
- CVSS 8.0 high
- 1.7% chance of exploitation in the next 30 days (EPSS)
- A fix is available