CVE-2025-54068

CRITICAL KEV NUCLEI

Laravel Livewire < 3.6.4 - Code Injection

Title source: rule

Description

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions. Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction. This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this version or later as soon as possible. No known workarounds are available.

Exploits (5)

nomisec WORKING POC 117 stars
by synacktiv · remote
https://github.com/synacktiv/Livepyre
nomisec WORKING POC 3 stars
by haxorstars · remote
https://github.com/haxorstars/CVE-2025-54068
nomisec SCANNER 3 stars
by z0d131482700x · poc
https://github.com/z0d131482700x/Livewire2025CVE
nomisec WORKING POC 1 stars
by flame-11 · remote-auth
https://github.com/flame-11/CVE-2025-54068-livewire
nomisec WORKING POC
by HelgeSverre · poc
https://github.com/HelgeSverre/livewire-honeypot

Nuclei Templates (1)

Laravel Livewire v3 - Remote Command Execution
CRITICALVERIFIEDby flame-11
Shodan: html:"wire:id"

Scores

CVSS v3 9.8
EPSS 0.5348
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2026-03-20
VulnCheck KEV 2026-02-17
ENISA EUVD EUVD-2025-21792
CWE
CWE-94
Status published
Products (3)
laravel/livewire 3.0.0 - 3.6.4
livewire/livewire 3.0.0-beta.1 - 3.6.4Packagist
livewire/livewire >= 3.0.0-beta.1, < 3.6.4
Published Jul 17, 2025
KEV Added Mar 20, 2026
Tracked Since Feb 18, 2026