CVE Tools

Laravel Livewire Vulnerability Exposes Over 6,000 Apps

Daily CyberSecurity (securityonline.info)

Reported exploitedLaravel LivewireWong Gen Deng

Our summary

A critical unauthenticated remote code execution issue in livewire/livewire (composer) has been actively exploited in the wild, tracked as CVE-2025-54068. Systems using versions >= 3.0.0-beta.1 and < 3.6.4 are at risk during Livewire property update hydration, which can allow attackers to run arbitrary code and steal secrets from environments, including database credentials and cloud/payment tokens. With CVE-2025-54068 patched in 3.6.4, organizations should upgrade immediately to limit widespread data exposure.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store