Laravel Livewire Code Injection Vulnerability
Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
CISA entryLaravel · AUTOMATIC DISCOVERY
Laravel is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.
Laravel is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Used by software teams to build, run or maintain applications.
Included in source projects, application dependencies, build systems or managed runtimes.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .
| Product | Laravel |
|---|---|
| Release | 11 |
| End of Active support | 3 September 2025 |
| End of Support | 12 March 2026 |
| Date precision | Day |
These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
CISA entryLaravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).
CISA entryLaravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().
CISA entryOSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
Version | PHP (*) | Release | Bug Fixes Until | Security Fixes Until | 11 | 8.2 - 8.4 | March 12th, 2024 | September 3rd, 2025 | March 12th, 2026
Publisher identity used by product-specific official-source collectors.
Open official vendor source