CVE-2026-54181: XSS
Summary
The Blade template for the color column type (src/resources/views/crud/columns/color.blade.php) has its escaped/unescaped rendering branches inverted relative to every other column template in the library. Because $column['escaped'] defaults to true, values stored in color columns are rendered unescaped by default, enabling Stored XSS if column values are not validated before storage.
Details
All other column templates in src/resources/views/crud/columns/ follow the convention: - $column['escaped'] == true → {{ $column['text'] }} (HTML-escaped) - $column['escaped'] == false → {!! $column['text'] !!} (raw)
The color template has these branches swapped. An attacker who can write an arbitrary string to a color-typed column can inject JavaScript that executes in the browser of any user who views the list — including administrators — with access to their session cookies and CSRF tokens.
Impact
Stored XSS with scope change (attacker context runs in victim's browser). Highest-risk target is an administrator viewing the list view. Exploitability requires the ability to write an unsanitized value into a color-typed column.
Patches
Fixed in 6.8.14 and 7.0.38 by correcting the branch order in color.blade.php. See PR #5992.
Workarounds
Validate stored color values against a strict CSS color grammar (e.g. /^#[0-9a-fA-F]{3,6}$/) at the model layer before data reaches the view.
Credits
Reported by Vishal Shukla (@shukla304) via sechub.dev.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/backpack/crudto a version that resolves this vulnerability.Fixed in 7.0.38 - Upgrade
Upgrade
composer/backpack/crudto a version that resolves this vulnerability.Fixed in 6.8.14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.8.14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.38 - Configuration
Fix the inverted escaped/unescaped rendering logic in color.blade.php by correcting the branch order so it matches the convention used by other templates (values are HTML-escaped by default when $column['escaped'] defaults to true).
Blade template: src/resources/views/crud/columns/color.blade.php escaped/unescaped branch order for $column['escaped'] rendering = correct branch order (ensure when $column['escaped'] == true values are HTML-escaped and when false values are rendered unescaped) - Configuration
Validate stored values for `color`-typed columns against a strict CSS color grammar (e.g., regex `^#[0-9a-fA-F]{3,6}$`) at the model layer before rendering to prevent Stored XSS.
Model validation (before data reaches view) stored color value validation (strict CSS color grammar) = /^#[0-9a-fA-F]{3,6}$/
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using a color-typed CRUD column are exposed if an attacker can store an arbitrary, unsanitized value in that column and a user later views the list. Administrators are the highest-risk viewers because injected script runs in their browser context.
Does this affect the default rendering behavior?
Yes. The color column's escaped setting defaults to true, but the affected template renders its text unescaped under that default. This differs from the intended behavior used by other column templates.
What must an attacker do to exploit it?
The attacker needs permission or another path to write a malicious string into a color-typed column without validation or sanitization. They also need a victim to open the list view containing the stored value.
What can be done before applying a fix?
Validate or sanitize all values written to color-typed columns so they cannot contain executable HTML or JavaScript. Restrict untrusted users from writing arbitrary values to those columns until the affected installation is updated.
How can teams identify potentially affected data?
Review color-typed column values for unexpected HTML, script content, or other markup, especially where those values can be supplied by less-trusted users. Also review list views that display such columns and the write paths that populate them.