Livewire Filemanager does not restrict uploaded file types
High severity
GitHub Reviewed
Published
Jan 16, 2026
to the GitHub Advisory Database
•
Updated Jan 23, 2026
Package
Affected versions
<= 1.0.4
Patched versions
None
Description
Published by the National Vulnerability Database
Jan 16, 2026
Published to the GitHub Advisory Database
Jan 16, 2026
Reviewed
Jan 20, 2026
Last updated
Jan 23, 2026
Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.
References