logo

Unpatched RCE: Livewire Filemanager Upload Flaw (CVE-2025-14894) Exposes Laravel Apps

ID: fb50e6e4-add9-5d17-8915-fdde7996148e

STIX ID: report--fb50e6e4-add9-5d17-8915-fdde7996148e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-19

Date Updated: 2026-04-23

Author: Ddos

...
...

Livewire Filemanager (CVE-2025-14894) contains a critical unauthenticated RCE flaw (CVSS 7.5) due to lack of file type/MIME validation; an attacker can upload a malicious PHP file and execute it if the application serves storage publicly (commonly via php artisan storage:link). No official patch is available, and CERT/CC advises checking and removing public serving of storage until mitigations are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.