CVE-2024-55661: Laravel Pulse Allows Remote Code Execution via Unprotected Query Method
(updated )
A vulnerability has been discovered in Laravel Pulse that could allow remote code execution through the public remember()
method in the Laravel\Pulse\Livewire\Concerns\RemembersQueries
trait. This method is accessible via Livewire components and can be exploited to call arbitrary callables within the application.
References
Detect and mitigate CVE-2024-55661 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →