CVE-2018-15133 is an unsafe PHP deserialization vulnerability in Laravel Framework versions through 5.5.40 and 5.6.x through 5.6.29. Laravel's encryption handling can decrypt and unserialize an attacker-controlled X-XSRF-TOKEN value. An attacker possessing the application's APP_KEY can create a valid encrypted serialized payload containing a usable Laravel PHP gadget chain, resulting in remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python proof-of-concept exploit for CVE-2018-15133, a remote code execution vulnerability in Laravel (<=5.5.40, 5.6.0-5.6.29) due to insecure deserialization of encrypted session cookies. The exploit requires the Laravel APP_KEY (in base64) and uses the PHPGGC tool to generate a malicious PHP object chain (Laravel/RCE5) that executes an arbitrary system command. The payload is encrypted using AES-CBC with the provided key, a random IV, and a calculated HMAC, mimicking Laravel's session structure. The resulting payload is base64-encoded and sent as the 'laravel_session' cookie in an HTTP request to the target domain. If the target is vulnerable and the key is correct, the command is executed on the server. The repository consists of two files: a detailed README.md (in Spanish) explaining the vulnerability, requirements, and usage, and exploit.py, which implements the exploit logic. The only code file is exploit.py, which is the entry point and orchestrates payload generation, encryption, and delivery. No hardcoded endpoints are present; the target domain is supplied by the user.
This repository provides a full proof-of-concept (PoC) environment and exploit for CVE-2018-15133, a critical unserialization vulnerability in Laravel <= 5.7.27. The structure includes a Dockerfile and docker-compose.yaml to build a vulnerable Laravel environment (PHP 7.2, Nginx, MySQL, Laravel 5.7.28), and an 'exploit.py' script that demonstrates remote code execution by abusing the APP_KEY encryption. The exploit works by crafting a malicious Python pickle object, encrypting it with the Laravel APP_KEY, and sending it as the XSRF-TOKEN cookie to the target Laravel application. If successful, arbitrary OS commands can be executed on the server. The repository also contains a full Laravel application source tree for testing. The exploit is a PoC and requires the attacker to know or obtain the APP_KEY from the target. No framework (e.g., Metasploit) is used; the exploit is standalone Python code.
This repository contains a single Metasploit module: 'laravel_token_unserialize_exec.rb', which exploits a remote command execution vulnerability in the PHP Laravel Framework (CVE-2018-15133, CVE-2017-16894). The exploit targets Laravel versions 5.5.40 and 5.6.x up to 5.6.29, leveraging insecure unserialize operations in the handling of the X-XSRF-TOKEN HTTP header. The module can also check for APP_KEY leakage via the /.env file or error messages. Successful exploitation allows an attacker to execute arbitrary system commands on the target server, typically resulting in a reverse shell. The module is weaponized, supporting customizable payloads via the Metasploit framework. The only file present is the exploit module itself, written in Ruby, and it is fully integrated with Metasploit's payload and session management.
This repository contains a Bash script (rce.sh) that automates exploitation of CVE-2018-15133, a remote code execution vulnerability in Laravel's PHPUnit integration. The script prompts the user for a target website URL, then sends a crafted HTTP request to the vulnerable eval-stdin.php endpoint, instructing the server to download and save a PHP web shell (lmao.php) from a public GitHub repository. After the shell is uploaded, the script attempts to open it in Firefox for interactive access. The repository structure is minimal, consisting of a README and the exploit script. The exploit is operational, providing a working payload and automating the attack process. Key endpoints include the vulnerable eval-stdin.php path and the location of the uploaded shell.
This repository provides a Python exploit script (pwn_laravel.py) targeting CVE-2018-15133, a remote code execution vulnerability in Laravel Framework (versions through 5.5.40 and 5.6.x through 5.6.29). The exploit works by crafting malicious PHP serialized objects, encrypting them with the Laravel APP_KEY, and sending them in the X-XSRF-TOKEN HTTP header to a specified Laravel endpoint. The script supports multiple gadget chains (four methods) for exploitation and allows both single command execution and interactive shell-like operation. The README.md provides background, usage instructions, and references. The requirements.txt lists Python dependencies, including cryptography and HTTP libraries. The main entry point is pwn_laravel.py, which is a standalone exploit and not part of a larger framework. The exploit requires knowledge of the target's APP_KEY and network access to the Laravel application.
This repository provides an operational exploit for CVE-2018-15133, a remote code execution vulnerability in Laravel Framework (through 5.5.40 and 5.6.x through 5.6.29) due to insecure deserialization of the X-XSRF-TOKEN cookie. The main script, 'larascript.py', is a Python3 tool that allows an attacker to send arbitrary system commands or establish a reverse shell on a vulnerable Laravel server, provided the attacker knows the application's APP_KEY. The script supports multiple payload types and reverse shell languages (bash, python, perl, php, ruby, nc, mkfifo, lua, java), and allows the user to specify the target URL, APP_KEY, command to execute, and reverse shell parameters. The repository includes a README with usage instructions, references to related exploits and resources, and a requirements.txt for dependencies. The exploit is not part of a larger framework and is self-contained. The attack vector is network-based, targeting Laravel applications accessible over HTTP(S) by sending malicious cookies. The main fingerprintable endpoint is the user-supplied target URL, and the exploit leverages the X-XSRF-TOKEN cookie for payload delivery.
This repository is a Proof of Concept (PoC) for exploiting CVE-2018-15133, a remote code execution vulnerability in Laravel Framework versions <= 5.6.29 (and <= 5.5.40). The repository contains: - A Dockerfile that builds a vulnerable Laravel 5.6.29 environment on PHP 7.2.10, exposing the application on http://localhost:8000 and adding a POST route for exploitation. - A README.md with detailed instructions for building, running, and exploiting the environment, including how to extract the APP_KEY, generate a malicious payload (using phpggc), encrypt it, and send it to the application via the X-XSRF-TOKEN HTTP header in a POST request. - The main exploit script (cve-2018-15133.php), which takes a base64-encoded APP_KEY and a base64-encoded serialized payload, encrypts the payload using AES-256-CBC, and outputs the value to be used in the X-XSRF-TOKEN header. The exploit demonstrates how an attacker with knowledge of the APP_KEY can achieve arbitrary command execution on a vulnerable Laravel instance by abusing the framework's unserialize logic. The attack vector is network-based, requiring HTTP POST access to the target. The main fingerprintable endpoints are the default web server (http://localhost:8000 in the PoC), the Laravel .env file (for APP_KEY extraction), and the root POST route. The exploit is a functional PoC and does not include weaponized automation or post-exploitation features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific CVE listed among vulnerabilities described as weaponized and accompanied by public proof-of-concept code in the actors' toolset.
A specific CVE referenced as weaponized within the actors' toolset; the content does not describe the flaw type or affected product.
A Laravel application-key deserialization vulnerability that can permit remote code execution when an application's APP_KEY is known or exposed.
A critical remote code execution vulnerability in the Laravel Framework due to insecure unserialization of encrypted cookies when the APP_KEY is known.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.