EXPOSURES › CVE-2018-15133
CVE-2018-15133
HIGH ⌖ ON CISA KEV · EXPLOITEDLaravel Framework's CVE-2018-15133 allows remote code execution if an attacker obtains the APP_KEY environment variable.
This vulnerability enables remote command execution in the widely used Laravel framework, posing a severe risk to DIB organizations relying on it for FedRAMP/NIST 800-171 compliance. Attackers can exploit this by accessing the APP_KEY to bypass security controls, potentially leading to data breaches and compliance violations. DIB orgs must immediately patch affected systems and audit all Laravel deployments for exposed encryption keys.
Shame score — A known RCE vulnerability in a widely-used framework that requires only an exposed encryption key to exploit, highlighting potential misconfiguration risks in DIB environments.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).