Livewire vulnerable to remote command execution during property update hydration
Description
Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions. Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction. This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this version or later as soon as possible. No known workarounds are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
livewire/livewirePackagist | >= 3.0.0-beta.1, < 3.6.4 | 3.6.4 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-29cq-5w36-x7w3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-54068ghsaADVISORY
- github.com/livewire/livewire/commit/ef04be759da41b14d2d129e670533180a44987dcghsax_refsource_MISCWEB
- github.com/livewire/livewire/releases/tag/v3.6.4ghsax_refsource_MISCWEB
- github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3ghsax_refsource_CONFIRMWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalogghsaWEB
- www.threathunter.ai/blog/iranian-threat-actor-tools-techniques-iocs-ioasghsaWEB
News mentions
1- Laravel Livewire Applications Compromised to Steal Credentials Exploiting RCE VulnerabilityCyber Security News · Jun 24, 2026