HIGH7.5
GHSA-9g95-48c6-r778
Livewire Filemanager does not restrict uploaded file types
Details
Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/livewire-filemanager/filemanager
Introduced in:
0No fixed version published yet for livewire-filemanager/filemanager (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-14894[ADVISORY]
- https://github.com/livewire-filemanager/filemanager[PACKAGE]
- https://github.com/livewire-filemanager/filemanager/blob/master/docs.md#security[WEB]
- https://hackingbydoing.wixsite.com/hackingbydoing/post/unauthenticated-rce-in-livewire-filemanager[WEB]
- https://www.kb.cert.org/vuls/id/650657[WEB]