
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14894 is an unauthenticated Remote Code Execution (RCE) vulnerability in Livewire Filemanager, a file management package commonly used in Laravel PHP applications. The flaw exists in LivewireFilemanagerComponent.php, which performs no file type or MIME validation, allowing attackers to upload malicious PHP files and execute them via the publicly accessible /storage/ URL. All versions prior to 1.0.0 are affected. The vulnerability was publicly disclosed on January 16, 2026, with CERT/CC issuing advisory VU#650657. It carries a CVSS v3.1 base score of 9.8 (Critical) (CERT/CC, Red Hat).
The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type): LivewireFilemanagerComponent.php applies no server-side validation of uploaded file extensions or MIME types, allowing PHP scripts to be stored alongside legitimate files (CERT/CC). Exploitation requires that the Laravel application has previously run php artisan storage:link, which creates a publicly web-accessible symlink at storage/app/public — a common and recommended setup step in Laravel deployments. Once a malicious PHP file is uploaded, an attacker can trigger its execution by requesting it via the /storage/ URL with a valid user ID, resulting in server-side PHP code execution. A technical write-up by the original reporter (HackingByDoing) is publicly available and was referenced in the CERT/CC advisory (CERT/CC).
Successful exploitation grants an unauthenticated attacker arbitrary code execution as the web server user on the affected host, enabling full read and write access to all files accessible by that account. This can lead to complete confidentiality, integrity, and availability compromise of the web application and its data, including database credentials, environment secrets, and user data stored in the Laravel application. The CERT/CC advisory further notes the capability to pivot and compromise other connected systems, making this a high-impact vulnerability with lateral movement potential (CERT/CC).
No authentication is required to exploit this vulnerability, and no user interaction is needed beyond the prerequisite storage:link setup, which is standard in most Laravel deployments. A public technical write-up detailing the exploitation technique was published by the original reporter (HackingByDoing) and is referenced in the CERT/CC advisory, lowering the barrier for exploitation (CERT/CC). The EPSS score is approximately 0.029% as of the time of reporting, suggesting limited automated exploitation activity so far (Red Hat). There is no confirmed evidence of in-the-wild exploitation or CISA KEV catalog listing at this time, and no specific threat actor attribution has been made.
/storage/ public directory and Livewire component signatures in HTTP responses.php artisan storage:link has been executed by checking if the /storage/ URL path is publicly accessible and returns files (e.g., https://target.com/storage/).LivewireFilemanagerComponent.php.shell.php containing <?php system($_GET['cmd']); ?>) — no authentication is required and no file type validation is enforced./storage/app/public/{user_id}/shell.php).https://target.com/storage/{user_id}/shell.php?cmd=id) to trigger server-side PHP execution and achieve RCE as the web server user (CERT/CC)..php file uploads; HTTP GET requests to /storage/ paths for .php files from external IP addresses..php files (especially with names like shell.php, cmd.php, or random strings) within the Laravel storage/app/public/ directory or its subdirectories; unexpected modification timestamps on files in the storage directory./storage/{user_id}/*.php; PHP error logs showing execution of unexpected commands or functions (system, exec, passthru, shell_exec).bash, curl, wget, python, nc) indicating command execution via the webshell (CERT/CC).As of the disclosure date (January 16, 2026), the vendor had not acknowledged the vulnerability or released a patch; however, version 1.0.0 was subsequently released and is the recommended upgrade target (GitHub). CERT/CC recommends checking whether php artisan storage:link has been executed and, if so, considering removal of the web-serving capability for the storage directory to prevent direct execution of uploaded files (CERT/CC). As an additional workaround, administrators should implement web server-level rules (e.g., Nginx/Apache configuration) to block direct HTTP execution of .php files within the /storage/ directory, and restrict access to the Livewire Filemanager interface to authenticated and authorized users only. The package's own README explicitly notes that file type validation is out of scope and that operators are responsible for securing uploaded content.
CERT/CC published advisory VU#650657 on January 16, 2026, crediting researcher HackingByDoing as the reporter and noting that neither the vendor (bee interactive), Laravel, nor Laravel Swiss had responded to notifications (CERT/CC). The vulnerability was covered by several security news outlets including CyberSecurityNews, SecurityOnline, and The Hacker News' weekly recap, highlighting the risk to Laravel applications using the package. Social media discussion appeared on Bluesky and Mastodon/Infosec.exchange, with community concern focused on the unauthenticated nature of the exploit and the commonality of the storage:link prerequisite in production deployments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."