Laravel Livewire v3 - Remote Command Execution
CVE-2025-54068
Verified
Description
Livewire v3 (Laravel) contains a vulnerability in its component hydration/update mechanism that can be exploited to reach remote command execution (RCE) without authentication under certain conditions.
Severity
Critical
CVSS Score
9.8
Exploit Probability
97%
Published Date
January 8, 2026
Template Author
flame-11
CVE-2025-54068.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2025-54068
CWE ID:
cwe-502
References
https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3https://github.com/synacktiv/Livepyrehttps://www.synacktiv.com/en/publications/livewire-remote-command-execution-through-unmarshalinghttps://www.synacktiv.com/sites/default/files/2025-09/slides-livewire-nullcon2025.pdfhttps://nvd.nist.gov/vuln/detail/CVE-2025-54068
Remediation Steps
Upgrade livewire/livewire to a patched version (>= 3.6.4).