CVE-2025-14894

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:livewire-filemanager:filemanager:*:*:*:*:*:*:*:*

History

23 Jan 2026, 17:04

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.8
CWE CWE-434
References () https://github.com/livewire-filemanager/filemanager - () https://github.com/livewire-filemanager/filemanager - Product
References () https://hackingbydoing.wixsite.com/hackingbydoing/post/unauthenticated-rce-in-livewire-filemanager - () https://hackingbydoing.wixsite.com/hackingbydoing/post/unauthenticated-rce-in-livewire-filemanager - Not Applicable
References () https://www.kb.cert.org/vuls/id/650657 - () https://www.kb.cert.org/vuls/id/650657 - Third Party Advisory
First Time Livewire-filemanager filemanager
Livewire-filemanager
CPE cpe:2.3:a:livewire-filemanager:filemanager:*:*:*:*:*:*:*:*

16 Jan 2026, 22:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

16 Jan 2026, 15:15

Type Values Removed Values Added
References
  • () https://www.kb.cert.org/vuls/id/650657 -

16 Jan 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 13:16

Updated : 2026-01-23 17:04


NVD link : CVE-2025-14894

Mitre link : CVE-2025-14894

CVE.ORG link : CVE-2025-14894


JSON object : View

Products Affected

livewire-filemanager

  • filemanager
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type