PT-2025-29947 · Livewire · Livewire

·

CVE-2025-54068

·

Published

2025-07-17

·

Updated

2026-07-16

CVSS v4.0

10

Critical

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Livewire versions 3.0 through 3.6.3
Description An issue in the hydration process of component property updates allows unauthenticated attackers to achieve remote command execution (RCE). The flaw occurs because the framework fails to verify submitted component state before deserializing it, enabling the injection of malicious serialized PHP objects via crafted HTTP requests. This process often utilizes PHPGGC gadget chains, which are sequences of existing legitimate PHP classes used to execute arbitrary code.
Real-world exploitation has been observed in a large-scale credential theft campaign affecting over 6,167 applications across sectors such as e-commerce, healthcare, financial services, and government. Attackers deployed a Bash script named shoc.enz to search for and exfiltrate sensitive .env files containing database passwords, AWS IAM keys, and Stripe secret keys. In other instances, the flaw was used to install unauthorized WordPress sites for black hat SEO and spam page generation.
Recommendations Update Livewire to version 3.6.4 or later.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05933
CVE-2025-54068
GHSA-29CQ-5W36-X7W3

Affected Products

Livewire