A critical OS command injection vulnerability (CVE-2026-53932) was discovered in the laravel-backup-restore package, which is used to restore database backups created with spatie/laravel-backup. Prior to version 1.9.4, an attacker could craft a malicious backup archive that triggers OS command injection during the database restore process. This could allow arbitrary command execution on the host system. The vulnerability has been patched in version 1.9.4. Users are strongly advised to upgrade immediately. The fix is available via the official GitHub repository commit and release.