CWE-CWE-502

Vulnerable Laravel Livewire version (CVE-2025-54068)

Severity:
Critical
Summary
Laravel Livewire v3 contains a vulnerability in the component hydration and update workflow. When a Livewire component is mounted and configured in specific ways, an attacker can craft a malicious update request that causes unsafe handling of attacker-influenced structured data during hydration. This can lead to unintended object handling / unserialization behavior and ultimately remote command execution in the context of the web server process. Because exploitation can be performed remotely and does not require authentication, successful attacks can result in full compromise of the affected application server.

Note: This detection is based on version identification.
Impact
Successful attacks of this vulnerability can result in takeover of the server.
Remediation
Upgrade to the latest patched version of Livewire
Required Skills for Successful Exploitation
Actions To Take
Classifications
Vulnerability Index

You can search and find all vulnerabilities

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding