Unpatched RCE: Livewire Filemanager Upload Flaw (CVE-2025-14894) Exposes Laravel Apps
ID: fb50e6e4-add9-5d17-8915-fdde7996148e
STIX ID: report--fb50e6e4-add9-5d17-8915-fdde7996148e
Feed Name: securityonline.info
Threat Score
Livewire Filemanager (CVE-2025-14894) contains a critical unauthenticated RCE flaw (CVSS 7.5) due to lack of file type/MIME validation; an attacker can upload a malicious PHP file and execute it if the application serves storage publicly (commonly via php artisan storage:link). No official patch is available, and CERT/CC advises checking and removing public serving of storage until mitigations are applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
