PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 4, 2026

Laravel Livewire v3 - Remote Command Execution

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-54068
9.2
CVSScritical
Exploitable remotely over the internet · no authentication required.

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions. Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction. This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this version or later as soon as possible. No known workarounds are available.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
livewireby livewire
>= 3.0.0-beta.1, < 3.6.4
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Laravel Livewire v3 - Remote Command Execution CVE-2025-54068 Scanner | S4E