CVE-2025-14894: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-14894 is an unauthenticated Remote Code Execution (RCE) vulnerability in Livewire Filemanager, a file management package commonly used in Laravel PHP applications. The flaw exists in LivewireFilemanagerComponent.php, which performs no file type or MIME validation, allowing attackers to upload malicious PHP files and execute them via the publicly accessible /storage/ URL. All versions prior to 1.0.0 are affected. The vulnerability was publicly disclosed on January 16, 2026, with CERT/CC issuing advisory VU#650657. It carries a CVSS v3.1 base score of 9.8 (Critical) (CERT/CC, Red Hat).

Technical details

The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type): LivewireFilemanagerComponent.php applies no server-side validation of uploaded file extensions or MIME types, allowing PHP scripts to be stored alongside legitimate files (CERT/CC). Exploitation requires that the Laravel application has previously run php artisan storage:link, which creates a publicly web-accessible symlink at storage/app/public — a common and recommended setup step in Laravel deployments. Once a malicious PHP file is uploaded, an attacker can trigger its execution by requesting it via the /storage/ URL with a valid user ID, resulting in server-side PHP code execution. A technical write-up by the original reporter (HackingByDoing) is publicly available and was referenced in the CERT/CC advisory (CERT/CC).

Impact

Successful exploitation grants an unauthenticated attacker arbitrary code execution as the web server user on the affected host, enabling full read and write access to all files accessible by that account. This can lead to complete confidentiality, integrity, and availability compromise of the web application and its data, including database credentials, environment secrets, and user data stored in the Laravel application. The CERT/CC advisory further notes the capability to pivot and compromise other connected systems, making this a high-impact vulnerability with lateral movement potential (CERT/CC).

Exploitability

No authentication is required to exploit this vulnerability, and no user interaction is needed beyond the prerequisite storage:link setup, which is standard in most Laravel deployments. A public technical write-up detailing the exploitation technique was published by the original reporter (HackingByDoing) and is referenced in the CERT/CC advisory, lowering the barrier for exploitation (CERT/CC). The EPSS score is approximately 0.029% as of the time of reporting, suggesting limited automated exploitation activity so far (Red Hat). There is no confirmed evidence of in-the-wild exploitation or CISA KEV catalog listing at this time, and no specific threat actor attribution has been made.

Exploitation steps

  1. Reconnaissance: Identify Laravel web applications using the Livewire Filemanager package (versions < 1.0.0) via Shodan, Censys, or by detecting the /storage/ public directory and Livewire component signatures in HTTP responses.
  2. Verify storage link: Confirm that php artisan storage:link has been executed by checking if the /storage/ URL path is publicly accessible and returns files (e.g., https://target.com/storage/).
  3. Locate the upload endpoint: Navigate to the Livewire Filemanager interface embedded in the application and identify the file upload functionality backed by LivewireFilemanagerComponent.php.
  4. Upload malicious PHP file: Submit a crafted HTTP request to the file upload endpoint with a PHP webshell payload (e.g., shell.php containing <?php system($_GET['cmd']); ?>) — no authentication is required and no file type validation is enforced.
  5. Retrieve the file path: After upload, note the storage path returned by the application, which includes a user ID component (e.g., /storage/app/public/{user_id}/shell.php).
  6. Execute the payload: Access the uploaded file via the public storage URL (e.g., https://target.com/storage/{user_id}/shell.php?cmd=id) to trigger server-side PHP execution and achieve RCE as the web server user (CERT/CC).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to Livewire Filemanager upload endpoints containing .php file uploads; HTTP GET requests to /storage/ paths for .php files from external IP addresses.
  • File System: Presence of .php files (especially with names like shell.php, cmd.php, or random strings) within the Laravel storage/app/public/ directory or its subdirectories; unexpected modification timestamps on files in the storage directory.
  • Logs: Laravel/web server access logs showing POST requests to the filemanager upload component followed by GET requests to /storage/{user_id}/*.php; PHP error logs showing execution of unexpected commands or functions (system, exec, passthru, shell_exec).
  • Process: Unusual child processes spawned by the PHP-FPM or Apache/Nginx worker process (e.g., bash, curl, wget, python, nc) indicating command execution via the webshell (CERT/CC).

Mitigation and workarounds

As of the disclosure date (January 16, 2026), the vendor had not acknowledged the vulnerability or released a patch; however, version 1.0.0 was subsequently released and is the recommended upgrade target (GitHub). CERT/CC recommends checking whether php artisan storage:link has been executed and, if so, considering removal of the web-serving capability for the storage directory to prevent direct execution of uploaded files (CERT/CC). As an additional workaround, administrators should implement web server-level rules (e.g., Nginx/Apache configuration) to block direct HTTP execution of .php files within the /storage/ directory, and restrict access to the Livewire Filemanager interface to authenticated and authorized users only. The package's own README explicitly notes that file type validation is out of scope and that operators are responsible for securing uploaded content.

Community reactions

CERT/CC published advisory VU#650657 on January 16, 2026, crediting researcher HackingByDoing as the reporter and noting that neither the vendor (bee interactive), Laravel, nor Laravel Swiss had responded to notifications (CERT/CC). The vulnerability was covered by several security news outlets including CyberSecurityNews, SecurityOnline, and The Hacker News' weekly recap, highlighting the risk to Laravel applications using the package. Social media discussion appeared on Bluesky and Mastodon/Infosec.exchange, with community concern focused on the unauthenticated nature of the exploit and the commonality of the storage:link prerequisite in production deployments.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management