PT-2025-29947 · Livewire · Livewire
Caleb Porzio
·
Published
2025-07-17
·
Updated
2026-05-05
·
CVE-2025-54068
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Livewire versions 3.0.0 through 3.6.3
Description
An issue in the Livewire full-stack framework for Laravel allows unauthenticated attackers to achieve remote command execution in specific scenarios. The problem arises from unsafe object unmarshaling during the hydration of certain component property updates. Exploitation requires a component to be mounted and configured in a particular way but does not require user interaction. Real-world incidents include the creation of spam pages, unauthorized redirects for SEO manipulation, and the installation of cryptocurrency miners on affected servers.
Recommendations
Update Livewire to version 3.6.4 or later.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Livewire