laravel
Safeguard articles tagged "laravel" — guides, analysis, and best practices for software supply chain and application security.
8 articles
CVE-2021-3129: Laravel Ignition File Upload Vulnerability
CVE-2021-3129 affects Laravel Ignition and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-09-18.
CVE-2018-15133: Laravel Deserialization of Untrusted Data Vulnerability
CVE-2018-15133 affects Laravel Laravel Framework and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-01-16.
CVE-2025-54068: Laravel Livewire Code Injection Vulnerability
CVE-2025-54068 affects Laravel Livewire and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-20.
Laravel Livewire's Hydration Flaw Let Attackers Skip Authentication Entirely
CVE-2025-54068 lets unauthenticated attackers achieve remote command execution in Laravel Livewire v3 through how component property updates are hydrated, with no known workaround.
Preventing open redirect vulnerabilities in Laravel
Laravel's own ->away() helper is documented as a bypass of its URL safety checks — feed it user input and you've built an open redirect, CWE-601, into the framework's happy path.
PHP Laravel security best practices
One line, `protected $guarded = [];`, can turn a Laravel signup form into an admin-account minting machine — here's how to lock down five real Laravel risk areas.
Security in PHP: Framework-Level Protections and Common Gaps
Security in PHP improved enormously once frameworks took over escaping, CSRF, and query building. The remaining incidents live in the gaps where developers step outside those rails.
Docker Laravel Security: Hardening Your PHP Container from Base Image to Runtime
A security-focused guide to running Laravel in Docker — non-root PHP-FPM, multi-stage builds, secret handling, and locking down the layers that leak.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.