CVE-2025-54068
Description
Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions. Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction. This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this version or later as soon as possible. No known workarounds are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
livewire/livewirePackagist | >= 3.0.0-beta.1, < 3.6.4 | 3.6.4 |
Affected products
3Patches
Vulnerability mechanics
References
8- github.com/livewire/livewire/commit/ef04be759da41b14d2d129e670533180a44987dcnvdPatchWEB
- github.com/advisories/GHSA-29cq-5w36-x7w3ghsaADVISORY
- github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-54068ghsaADVISORY
- www.threathunter.ai/blog/iranian-threat-actor-tools-techniques-iocs-ioas/nvdThird Party Advisory
- github.com/livewire/livewire/releases/tag/v3.6.4nvdRelease NotesWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government ResourceWEB
- www.threathunter.ai/blog/iranian-threat-actor-tools-techniques-iocs-ioasghsaWEB
News mentions
3- Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli OrganizationsThe Hacker News · Jul 6, 2026
- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News · Jul 6, 2026
- Laravel Livewire Applications Compromised to Steal Credentials Exploiting RCE VulnerabilityCyber Security News · Jun 24, 2026