CVE-2024-55661: Laravel Pulse Allows Remote Code Execution via Unprotected Query Method
A vulnerability has been discovered in Laravel Pulse that could allow remote code execution through the public remember() method in the Laravel\Pulse\Livewire\Concerns\RemembersQueries trait. This method is accessible via Livewire components and can be exploited to call arbitrary callables within the application.
Impact
An authenticated user with access to Laravel Pulse dashboard can execute arbitrary code by calling any function or static method that meets the following criteria:
- The callable is a function or static method - The callable has no parameters or no strict parameter types
Vulnerable Components
- The remember(callable $query, string $key = '') method in Laravel\Pulse\Livewire\Concerns\RemembersQueries - Affects all Pulse card components that use this trait
Attack Vectors
The vulnerability can be exploited through Livewire component interactions, for example:
php wire:click="remember('\\Illuminate\\Support\\Facades\\Config::all', 'config')"
Credit
Thank you to Jeremy Angele for reporting this vulnerability.
Other sources
Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discovered in Laravel Pulse prior to version 1.3.1 that could allow remote code execution through the public remember() method in the Laravel\Pulse\Livewire\Concerns\RemembersQueries trait. This method is accessible via Livewire components and can be exploited to call arbitrary callables within the application. An authenticated user with access to Laravel Pulse dashboard can execute arbitrary code by calling any function or static method in which the callable is a function or static method and the callable has no parameters or no strict parameter types. The vulnerable to component is remember(callable $query, string $key = '') method in Laravel\Pulse\Livewire\Concerns\RemembersQueries, and the vulnerability affects all Pulse card components that use this trait. Version 1.3.1 contains a patch.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55661?
CVE-2024-55661 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-55661?
To fix CVE-2024-55661, update the Laravel Pulse package to version 1.3.1 or later.
What components are affected by CVE-2024-55661?
CVE-2024-55661 affects the Laravel Pulse package, specifically through the public remember() method in the Livewire components.
Can CVE-2024-55661 allow unauthorized access?
Yes, CVE-2024-55661 can allow unauthorized access as it enables remote code execution through exploited Livewire components.
What is Laravel Pulse's role in CVE-2024-55661?
Laravel Pulse is the vulnerable package in CVE-2024-55661, which allows execution of arbitrary code via a specific method.