PT-2026-3246 · Laravel +1 · Laravel +1

Published

2026-01-16

·

Updated

2026-01-19

·

CVE-2025-14894

CVSS v3.1
7.5
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Livewire Filemanager (affected versions not specified)
Description Livewire Filemanager, often used with Laravel applications, has a component,
LivewireFilemanagerComponent.php
, that lacks proper file type and MIME validation. This allows for remote code execution by uploading a malicious PHP file. If a standard Laravel application setup is in place, this file can be executed through the '/storage/' URL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2025-14894

Affected Products

Laravel
Livewire Filemanager