CVE-2025-14894 affects Livewire Filemanager, a component commonly used in Laravel applications. This critical vulnerability (CVSS 9.8) stems from inadequate file type and MIME validation in LivewireFilemanagerComponent.php, enabling unauthenticated remote code execution (RCE) by uploading and executing malicious PHP files. Exploitation is possible if a common Laravel setup allows access to the /storage/ URL. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness despite its inactive status on the CISA KEV list.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0CPE matchmatch criteria | cpe:2.3:a:livewire-filemanager:filemanager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.