Description

A severe remote command execution (RCE) vulnerability, CVE-2025-54068, has been found in Livewire, the highly used full-stack Laravel framework. As Livewire is used that much—more than 53 million downloads—the flaw poses a significant danger to tens of millions of Laravel-based web applications worldwide. The issue directly affects Livewire v3.x and not Livewire v2, which is immune. The absence of authentication in the vulnerability and that it is capable of executing code remotely make this one of the worst Laravel-related bugs to have ever existed. A fixed version, v3.6.4, has been released by the Livewire team to remove the issue. Recommendations: Patching is required urgently. All Laravel developers using Livewire version 3.x must update to Livewire version 3.6.4 or higher as a matter of urgency. There is no workaround available, and the vulnerability is exploitable even in publicly available apps with minimal configuration. Security teams must scan their apps for usage of Livewire v3, especially custom components, and make sure all environments are updated.