Skip to content
COOEY

EXPOSURES › CVE-2025-54068

CVE-2025-54068

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-03-20 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-54068 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildsupply-chain

Laravel Livewire allows unauthenticated attackers to execute remote commands via code injection.

This vulnerability enables remote code execution in Laravel Livewire without authentication, posing a severe risk to defense contractors relying on Livewire for secure applications. DIB organizations must immediately patch their dependencies and audit all Livewire-enabled services to prevent unauthorized command execution.

Shame score — An unauthenticated RCE in a widely used framework component is a critical failure that undermines trust in the software supply chain.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.