Livewire是Livewire开源的一个 Laravel 的全栈框架,允许您在不离开 PHP 的情况下构建动态 UI 组件。 Livewire 3.6.3及之前版本存在代码注入漏洞,该漏洞源于组件属性更新处理不当,可能导致远程命令执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known. | https://github.com/synacktiv/Livepyre | POC Details |
| 2 | https://github.com/vulhub/vulhub/blob/master/livewire/CVE-2025-54068/README.md | POC Details | |
| 3 | Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into safe.txt. | https://github.com/z0d131482700x/Livewire2025CVE | POC Details |
| 4 | None | https://github.com/flame-11/CVE-2025-54068-livewire | POC Details |
| 5 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E5%BC%80%E5%8F%91%E6%A1%86%E6%9E%B6%E6%BC%8F%E6%B4%9E/Livewire%20%E7%BB%84%E4%BB%B6%E5%B1%9E%E6%80%A7%20hydrate%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2025-54068.md | POC Details |
| 6 | Livewire v3 (Laravel) contains a vulnerability in its component hydration/update mechanism that can be exploited to reach remote command execution (RCE) without authentication under certain conditions. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-54068.yaml | POC Details |
| 7 | A tool designed to exploit CVE-2025-54068 and Remote Command Execution of the Livewire project. | https://github.com/haxorstars/CVE-2025-54068 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet