CVE-2024-55661: Laravel Pulse Allows Remote Code Execution via Unprotected Query Method

Published Dec 13, 2024
·
Updated

A vulnerability has been discovered in Laravel Pulse that could allow remote code execution through the public remember() method in the Laravel\Pulse\Livewire\Concerns\RemembersQueries trait. This method is accessible via Livewire components and can be exploited to call arbitrary callables within the application.

Impact

An authenticated user with access to Laravel Pulse dashboard can execute arbitrary code by calling any function or static method that meets the following criteria:

- The callable is a function or static method - The callable has no parameters or no strict parameter types

Vulnerable Components

- The remember(callable $query, string $key = '') method in Laravel\Pulse\Livewire\Concerns\RemembersQueries - Affects all Pulse card components that use this trait

Attack Vectors

The vulnerability can be exploited through Livewire component interactions, for example:

php wire:click="remember('\\Illuminate\\Support\\Facades\\Config::all', 'config')"

Credit

Thank you to Jeremy Angele for reporting this vulnerability.

Other sources

Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discovered in Laravel Pulse prior to version 1.3.1 that could allow remote code execution through the public remember() method in the Laravel\Pulse\Livewire\Concerns\RemembersQueries trait. This method is accessible via Livewire components and can be exploited to call arbitrary callables within the application. An authenticated user with access to Laravel Pulse dashboard can execute arbitrary code by calling any function or static method in which the callable is a function or static method and the callable has no parameters or no strict parameter types. The vulnerable to component is remember(callable $query, string $key = '') method in Laravel\Pulse\Livewire\Concerns\RemembersQueries, and the vulnerability affects all Pulse card components that use this trait. Version 1.3.1 contains a patch.

NVD

Affected Software

2 affected componentsFixes available
composer/laravel/pulse<1.3.1
1.3.1
Laravel Pulse<1.3.1

Event History

Dec 13, 2024
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyAffected Software
Advisory Published
via GitHub·08:35 PM
Jun 9, 2025
Exploit Published
12:00 AM
Known Exploited
06:24 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-55661?

CVE-2024-55661 is considered a critical vulnerability due to its potential for remote code execution.

2

How do I fix CVE-2024-55661?

To fix CVE-2024-55661, update the Laravel Pulse package to version 1.3.1 or later.

3

What components are affected by CVE-2024-55661?

CVE-2024-55661 affects the Laravel Pulse package, specifically through the public remember() method in the Livewire components.

4

Can CVE-2024-55661 allow unauthorized access?

Yes, CVE-2024-55661 can allow unauthorized access as it enables remote code execution through exploited Livewire components.

5

What is Laravel Pulse's role in CVE-2024-55661?

Laravel Pulse is the vulnerable package in CVE-2024-55661, which allows execution of arbitrary code via a specific method.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203