Executive brief
Laravel Livewire, a popular framework for building interactive web interfaces, contains a critical security flaw that allows attackers to execute unauthorized commands on the server. This vulnerability can be exploited over the internet without needing a username or password, potentially leading to a full system takeover or data breach. Organizations using Livewire version 3 should update to version 3.6.4 immediately to protect their operations and customer data.
Technical details
A code injection vulnerability (CWE-94) exists in Laravel Livewire v3 due to the improper hydration of certain component property updates. An unauthenticated remote attacker can exploit this by sending specially crafted requests to a server where a Livewire component is mounted and configured in a specific manner. Successful exploitation allows for arbitrary remote code execution (RCE) on the underlying host. This issue is specific to Livewire v3 and does not affect earlier major versions. The vulnerability has been observed being exploited in the wild by threat actors. A fix is available in version 3.6.4.
Affected products
- Laravel Livewire v3.0.0 to v3.6.3
Timeline
- 2025-07-17: disclosed: Initial NVD publication and vendor advisory
- 2025-07-17: patched: Fixed in version 3.6.4
- 2026-03-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-03-20: exploited: Confirmed exploitation in the wild by threat actors