Vulnerability record · CVE-2018-15133 · published 9 August 2018
CVE-2018-15133: Laravel Framework X-XSRF-TOKEN deserialization leads to RCE
Laravel · Laravel
Laravel Framework through 5.5.40 and 5.6.x through 5.6.29 may unserialize an untrusted X-XSRF-TOKEN value, allowing remote code execution via the decrypt method in Illuminate/Encryption/Encrypter.php and a phpggc gadget chain. The flaw matters because it turns a request header into a code execution path, though the attacker must first know the application key.
Description
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with a very high EPSS score and enables remote code execution, despite the application key precondition.
What it is
Laravel Framework through 5.5.40 and 5.6.x through 5.6.29 may unserialize an untrusted X-XSRF-TOKEN value, allowing remote code execution via the decrypt method in Illuminate/Encryption/Encrypter.php and a phpggc gadget chain. The flaw matters because it turns a request header into a code execution path, though the attacker must first know the application key.
Impact
An attacker who knows the application key can execute arbitrary code on the server, leading to full compromise of the application and its data.
Attack surface
Reached remotely over the network by sending a crafted X-XSRF-TOKEN header; no authentication or user interaction is required per the CVSS vector, but the application key must be known.
Exploitation
CISA added this to KEV on 2024-01-16, EPSS 30-day probability is 0.76814 (99.5th percentile), and references include an exploit write-up, indicating active exploitation.
What to do
- Upgrade Laravel to 5.6.30 or later, or the corresponding fixed release for your branch, per the vendor upgrade guide.
- Rotate the application key (APP_KEY) if exposure is suspected, since key knowledge is the precondition for exploitation.
- Restrict or filter X-XSRF-TOKEN handling and validate tokens before any deserialization path.
- If patching is not possible, discontinue use of the affected product as CISA advises.
- Review logs for prior privileged access or compromise that could have leaked the application key.
Detection
- Inspect HTTP request logs for unusual or malformed X-XSRF-TOKEN header values.
- Monitor for unexpected outbound connections or process execution from the Laravel application.
- Alert on deserialization errors or exceptions from Illuminate/Encryption/Encrypter.php.
- Correlate application key access or exposure events with subsequent anomalous requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-15133 to the Known Exploited Vulnerabilities catalog on 16 January 2024 as "Laravel Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 6 February 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/153641/PHP-Laravel-Framework-Token-Unserialize-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://laravel.com/docs/5.6/upgrade#upgrade-5.6.30 | Vendor Advisory |
| http://packetstormsecurity.com/files/153641/PHP-Laravel-Framework-Token-Unserialize-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://laravel.com/docs/5.6/upgrade#upgrade-5.6.30 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-15133 | US Government Resource |
Track CVE-2018-15133 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-15133), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.