CVE-2025-14894

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:livewire-filemanager:filemanager:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-16 13:16

Updated : 2026-01-23 17:04


NVD link : CVE-2025-14894

Mitre link : CVE-2025-14894

CVE.ORG link : CVE-2025-14894


JSON object : View

Products Affected

livewire-filemanager

  • filemanager
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type