Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.
History

Mon, 19 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Bee Interactive
Bee Interactive livewire Filemanager
Vendors & Products Bee Interactive
Bee Interactive livewire Filemanager

Fri, 16 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 15:30:00 +0000

Type Values Removed Values Added
References

Fri, 16 Jan 2026 13:00:00 +0000

Type Values Removed Values Added
Description Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.
Title CVE-2025-14894
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-01-16T21:44:06.442Z

Reserved: 2025-12-18T16:01:40.573Z

Link: CVE-2025-14894

cve-icon Vulnrichment

Updated: 2026-01-16T15:04:56.329Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-16T13:16:11.220

Modified: 2026-01-16T22:16:18.110

Link: CVE-2025-14894

cve-icon Redhat

No data.