Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-54068

98
FAUCET Score

CVE-2025-54068 is a critical Remote Command Execution (RCE) vulnerability affecting Laravel Livewire v3, specifically versions up to and including v3.6.3. This flaw allows unauthenticated attackers to execute arbitrary commands due to improper component property hydration, requiring a specific component configuration. With a CVSS score of 9.8 (Critical) and a FAUCET Risk Score of 96.0, it presents a severe risk with low attack complexity and no user interaction required. The vulnerability is actively exploited in the wild, confirmed by its inclusion in CISA's KEV catalog, and public exploit intelligence like Nuclei templates are available. All users are strongly urged to upgrade to Livewire v3.6.4 or later immediately, as no workarounds exist.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, < 3.6.4CPE matchmatch criteria
cpe:2.3:a:laravel:livewire:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.2CRITICAL

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
95.38%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Mar 20, 2026
Nuclei: CVE-2025-54068 · Jan 8, 2026
This CVE's current EPSS score of 0.9538 is in the 99th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

composerpatch availablevia ghsa
Product: livewire/livewireFixed in: 3.6.4
github_advisorypatch availablevia nvd_reference
View patch
asuswrtvendor investigatingvia llm_extracted
audiobookshelfvendor investigatingvia llm_extracted
datadogvendor investigatingvia llm_extracted
invoiceplanevendor investigatingvia llm_extracted
lycheeorgvendor investigatingvia llm_extracted
nutanixvendor investigatingvia llm_extracted
phpofficevendor investigatingvia llm_extracted

Vendor Advisories (8)

invoiceplanellm-invoiceplane-46597a96e6050706CRITICAL

CVE-2025-54068 (9.8) leads to crypto miner running inside Lychee 5.3.0 container

Feb 4, 2026
lycheeorgllm-lycheeorg-5ee20e4d64a95f17CRITICAL

CVE-2025-54068 (9.8) leads to crypto miner running inside Lychee 5.3.0 container

Feb 4, 2026
audiobookshelfllm-audiobookshelf-9394258e6dddc0eeCRITICAL

CVE-2025-54068 (9.8) leads to crypto miner running inside Lychee 5.3.0 container

Feb 4, 2026
datadogllm-datadog-83259fa07e323786CRITICAL

CVE-2025-54068 (9.8) leads to crypto miner running inside Lychee 5.3.0 container

Feb 4, 2026
phpofficellm-phpoffice-52973ee2b4d30d58CRITICAL

CVE-2025-54068 (9.8) leads to crypto miner running inside Lychee 5.3.0 container

Feb 4, 2026
asuswrtllm-asuswrt-43370070089ab50cCRITICAL

CVE-2025-54068 (9.8) leads to crypto miner running inside Lychee 5.3.0 container

Feb 4, 2026
nutanixllm-nutanix-2d4d3f0bf79ef23bCRITICAL

CVE-2025-54068 (9.8) leads to crypto miner running inside Lychee 5.3.0 container

Feb 4, 2026
composerGHSA-29cq-5w36-x7w3critical

Livewire is vulnerable to remote command execution during component property update hydration

Jul 17, 2025

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
threathunter.ai / blog/iranian-threat-actor-tools-techniques-iocs-ioas
Third Party Advisory
github.com / livewire/livewire/commit/ef04be759da41b14d2d129e670533180a44987dc
Patch
github.com / livewire/livewire/releases/tag/v3.6.4
Release Notes
github.com / livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3
Vendor Advisory