Vulnerability Description
Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Livewire-Filemanager | Filemanager | < 1.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/livewire-filemanager/filemanagerProduct
- https://hackingbydoing.wixsite.com/hackingbydoing/post/unauthenticated-rce-in-liNot Applicable
- https://www.kb.cert.org/vuls/id/650657Third Party Advisory
FAQ
What is CVE-2025-14894?
CVE-2025-14894 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malic...
How severe is CVE-2025-14894?
CVE-2025-14894 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-14894?
Check the references section above for vendor advisories and patch information. Affected products include: Livewire-Filemanager Filemanager.