/Vulnerability Library

Laravel Livewire v3 - Remote Command Execution

CVE-2025-54068
Verified

Description

Livewire v3 (Laravel) contains a vulnerability in its component hydration/update mechanism that can be exploited to reach remote command execution (RCE) without authentication under certain conditions.

Severity

Critical

CVSS Score

9.8

Exploit Probability

97%

Published Date

January 8, 2026

Template Author

flame-11

CVE-2025-54068.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2025-54068
CWE ID:
cwe-502

References

https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3https://github.com/synacktiv/Livepyrehttps://www.synacktiv.com/en/publications/livewire-remote-command-execution-through-unmarshalinghttps://www.synacktiv.com/sites/default/files/2025-09/slides-livewire-nullcon2025.pdfhttps://nvd.nist.gov/vuln/detail/CVE-2025-54068

Remediation Steps

Upgrade livewire/livewire to a patched version (>= 3.6.4).