A high-severity vulnerability in Livewire Filemanager, a file-management component used in Laravel web applications, allows unauthenticated remote code execution via malicious file upload. Tracked as CVE-2025-14894 (CERT/CC note VU#650657; reported CVSS 7.5), the issue stems from inadequate file-type and MIME validation in LivewireFilemanagerComponent.php, enabling attackers to upload a PHP payload (e.g., a webshell) through the component’s upload interface.
Exploitation is straightforward in common Laravel deployments: if the application exposes uploaded content through the public /storage/ path—typically after running the standard setup command php artisan storage:link—an attacker can upload a malicious PHP file and then trigger execution by requesting it via the storage URL. Successful exploitation runs code with the privileges of the web server user, enabling broad read/write access to accessible files and potential pivoting to connected systems; at the time of reporting, the issue was described as unpatched/unacknowledged by the vendor, with the project’s documentation reportedly treating file validation as “out of scope” for the component itself.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
At the time of disclosure, no official patch was available for CVE-2025-14894 and the vendor had not acknowledged the vulnerability, according to the advisory coverage. This left defenders reliant on configuration changes and upload restrictions as interim mitigations.
The disclosure explained that Laravel deployments exposing uploaded files through the public /storage/ path, commonly after using `php artisan storage:link`, can allow execution of uploaded PHP payloads as the web server user. CERT/CC recommended mitigations including disabling public serving of storage, enforcing strict allowlisted upload validation, and storing uploads outside web-accessible directories.
On 2026-01-16, CERT/CC disclosed CVE-2025-14894 (VU#650657), a vulnerability in Livewire Filemanager that can allow unauthenticated remote code execution through malicious file uploads. The issue was attributed to missing file type and MIME validation, which can let attackers upload PHP payloads disguised as benign files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.