Detects Laravel Livewire v3 instances (3.0.0–3.6.3) where the component property update hydration mechanism allows unauthenticated attackers to smuggle malicious synthesizers through the updates payload, triggering a GuzzleHttp\Psr7\FnStream gadget chain for arbitrary command execution without needing the APP_KEY.
Is your app exploitable through CVE-2025-54068?
Scan your domain free