PT-2025-29947 · Livewire · Livewire

Caleb Porzio

·

Published

2025-07-17

·

Updated

2026-05-05

·

CVE-2025-54068

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Livewire versions 3.0.0 through 3.6.3
Description An issue in the Livewire full-stack framework for Laravel allows unauthenticated attackers to achieve remote command execution in specific scenarios. The problem arises from unsafe object unmarshaling during the hydration of certain component property updates. Exploitation requires a component to be mounted and configured in a particular way but does not require user interaction. Real-world incidents include the creation of spam pages, unauthorized redirects for SEO manipulation, and the installation of cryptocurrency miners on affected servers.
Recommendations Update Livewire to version 3.6.4 or later.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-05933
CVE-2025-54068
GHSA-29CQ-5W36-X7W3

Affected Products

Livewire