Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9g95-48c6-r778 Livewire Filemanager does not restrict uploaded file types
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 23 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Livewire-filemanager
Livewire-filemanager filemanager
Weaknesses CWE-434
CPEs cpe:2.3:a:livewire-filemanager:filemanager:*:*:*:*:*:*:*:*
Vendors & Products Livewire-filemanager
Livewire-filemanager filemanager

Mon, 19 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Bee Interactive
Bee Interactive livewire Filemanager
Vendors & Products Bee Interactive
Bee Interactive livewire Filemanager

Fri, 16 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 15:30:00 +0000

Type Values Removed Values Added
References

Fri, 16 Jan 2026 13:00:00 +0000

Type Values Removed Values Added
Description Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.
Title CVE-2025-14894
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-01-16T21:44:06.442Z

Reserved: 2025-12-18T16:01:40.573Z

Link: CVE-2025-14894

cve-icon Vulnrichment

Updated: 2026-01-16T15:04:56.329Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-16T13:16:11.220

Modified: 2026-01-23T17:04:25.370

Link: CVE-2025-14894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-19T09:20:56Z

Weaknesses