Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.
References
| Link | Resource |
|---|---|
| https://github.com/livewire-filemanager/filemanager | Product |
| https://hackingbydoing.wixsite.com/hackingbydoing/post/unauthenticated-rce-in-livewire-filemanager | Not Applicable |
| https://www.kb.cert.org/vuls/id/650657 | Third Party Advisory |
Configurations
History
23 Jan 2026, 17:04
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CWE | CWE-434 | |
| References | () https://github.com/livewire-filemanager/filemanager - Product | |
| References | () https://hackingbydoing.wixsite.com/hackingbydoing/post/unauthenticated-rce-in-livewire-filemanager - Not Applicable | |
| References | () https://www.kb.cert.org/vuls/id/650657 - Third Party Advisory | |
| First Time |
Livewire-filemanager filemanager
Livewire-filemanager |
|
| CPE | cpe:2.3:a:livewire-filemanager:filemanager:*:*:*:*:*:*:*:* |
16 Jan 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
16 Jan 2026, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Jan 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-16 13:16
Updated : 2026-01-23 17:04
NVD link : CVE-2025-14894
Mitre link : CVE-2025-14894
CVE.ORG link : CVE-2025-14894
JSON object : View
Products Affected
livewire-filemanager
- filemanager
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
