vulnerability

Laravel Livewire: CVE-2025-54068: Remote Code Execution via Unsafe Unmarshaling

Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:N)
Published
Jul 17, 2025
Added
Apr 14, 2026
Modified
Apr 14, 2026

Description

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows
unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain
component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions.
Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction.
This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this version or later as soon as possible.
No known workarounds are available.

Solution

laravel-livewire-upgrade-3-6-4
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.