CVE-2025-56399 affects alexusmai laravel-file-manager 3.3.1 and earlier. An authenticated attacker can upload a crafted file using the file manager interface where the filename uses a .png` extension and the file contents contain PHP code. Although the upload appears to be rejected by client-side validation, the file is still written to the server. The attacker can then invoke the application's rename API to change the uploaded file's extension to .php. If the resulting file is reachable through a public URL and processed by the web server's PHP handler, requesting that file causes execution of the embedded PHP code, resulting in remote code execution. The issue is fundamentally an unrestricted or improperly validated file upload combined with unsafe post-upload file renaming and executable web exposure.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python 2 exploit PoC for CVE-2025-56399 affecting alexusmai/laravel-file-manager <= 3.3.1. The repo contains three files: README.md with vulnerability and usage documentation, lfm.py as the main exploit script, and requirements.txt listing requests and colorama. The exploit is not part of a larger framework. The main capability is authenticated remote code execution through unrestricted file upload. The script accepts a list of target base URLs, probes several common Laravel FileManager integration paths, and identifies a vulnerable instance by checking for the marker string vendor/file-manager/js/file-manager.js in the returned HTML. It then extracts a CSRF token from either a meta tag or hidden form field, calls /file-manager/initialize to obtain the configured disk key, and uses /file-manager/upload to upload two files: a .htaccess file and a PHP web shell disguised with image/gif content type. After upload, the script calls /file-manager/url?disk=...&path=... to obtain the public URL of the uploaded file. It verifies exploitation by requesting the shell with ?shinday=1 and checking for the string 'Shinday'. Successful shell URLs are appended to valid.txt. The embedded PHP payload acts as a simple web shell: when activated with the query parameter, it prints php_uname output and exposes a file upload form for staging additional tools; otherwise it emits a minimal GIF89a image to appear benign. Operationally, the script uses requests.Session, disables TLS verification warnings, and processes targets concurrently with a 5-thread pool. This is a real exploit rather than a detector-only script because it performs upload, deployment, and execution verification of a server-side payload.
Repository contains a small standalone Python mass-exploitation tool for CVE-2025-56399 targeting alexusmai/laravel-file-manager, with two near-duplicate implementations: a synchronous threaded version using requests (CVE-2025-56399.py) and an asynchronous version using httpx (CVE-2025-56399-httpx.py). Supporting files are README.md, requirements.txt, LICENSE, and .gitignore. Core capability: the scripts take a user-supplied target list, normalize each entry into HTTP/HTTPS base URLs, probe several Laravel File Manager initialize endpoints, attempt to obtain a CSRF token from the file manager UI, site root, or a list of common public/auth pages, then derive related /upload and /url endpoints. They generate a random PHP file name and a simple PHP web shell payload that prints a marker and exposes a secondary file-upload form. After upload, the code requests the resulting shell URL and classifies it as CONFIRMED, UPLOADED, or UNVERIFIED based on marker presence and HTTP response. The exploit is not just a detector: it actively attempts file upload and persistence via a web shell. It is operational rather than framework-based, with hardcoded behavior and limited customization. The code includes concurrency controls (50 threads/workers), randomized User-Agent support via fake-useragent, CSRF scraping via regex, and output logging to vulnerable.txt and uploaded.txt. No external C2 or hardcoded remote infrastructure is present; all network interaction is directed at user-provided targets and the enumerated application paths.
This repository documents a proof-of-concept (PoC) exploit for CVE-2025-56399, an authenticated remote code execution (RCE) vulnerability in laravel-file-manager versions 3.3.1 and below. The repository contains two markdown files: a detailed PoC walkthrough (CVE-2025-56399/POC-CVE-56399.md) and a README summarizing the vulnerability, impact, and remediation. No executable code is present; the PoC is described step-by-step with screenshots and example payloads. The exploit leverages the ability for authenticated users to upload files with allowed extensions (e.g., .png, .pdf) containing PHP code, then rename them to .php, or to directly create and edit .php files. Once the malicious file is accessible via a public URL (e.g., http://server-ip-address/storage/php.php), the attacker can execute arbitrary PHP code, achieving RCE. The repository is intended for educational and disclosure purposes, providing clear instructions for reproducing the vulnerability and understanding its impact.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.