← Vulnerability feed

Vulnerability record · CVE-2018-15133 · published 9 August 2018

CVE-2018-15133: Laravel Framework X-XSRF-TOKEN deserialization leads to RCE

Laravel · Laravel

Laravel Framework through 5.5.40 and 5.6.x through 5.6.29 may unserialize an untrusted X-XSRF-TOKEN value, allowing remote code execution via the decrypt method in Illuminate/Encryption/Encrypter.php and a phpggc gadget chain. The flaw matters because it turns a request header into a code execution path, though the attacker must first know the application key.

8.1 CVSS 3.1 High CISA KEV since 16 Jan 2024 EPSS 77% · top 0.5% CWE-502 · Deserialization of untrusted data
8.1CVSS 3.1 base score, v2 6.8
77%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with a very high EPSS score and enables remote code execution, despite the application key precondition.

What it is

Laravel Framework through 5.5.40 and 5.6.x through 5.6.29 may unserialize an untrusted X-XSRF-TOKEN value, allowing remote code execution via the decrypt method in Illuminate/Encryption/Encrypter.php and a phpggc gadget chain. The flaw matters because it turns a request header into a code execution path, though the attacker must first know the application key.

Impact

An attacker who knows the application key can execute arbitrary code on the server, leading to full compromise of the application and its data.

Attack surface

Reached remotely over the network by sending a crafted X-XSRF-TOKEN header; no authentication or user interaction is required per the CVSS vector, but the application key must be known.

Exploitation

CISA added this to KEV on 2024-01-16, EPSS 30-day probability is 0.76814 (99.5th percentile), and references include an exploit write-up, indicating active exploitation.

What to do

  • Upgrade Laravel to 5.6.30 or later, or the corresponding fixed release for your branch, per the vendor upgrade guide.
  • Rotate the application key (APP_KEY) if exposure is suspected, since key knowledge is the precondition for exploitation.
  • Restrict or filter X-XSRF-TOKEN handling and validate tokens before any deserialization path.
  • If patching is not possible, discontinue use of the affected product as CISA advises.
  • Review logs for prior privileged access or compromise that could have leaked the application key.

Detection

  • Inspect HTTP request logs for unusual or malformed X-XSRF-TOKEN header values.
  • Monitor for unexpected outbound connections or process execution from the Laravel application.
  • Alert on deserialization errors or exceptions from Illuminate/Encryption/Encrypter.php.
  • Correlate application key access or exposure events with subsequent anomalous requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-15133 to the Known Exploited Vulnerabilities catalog on 16 January 2024 as "Laravel Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 6 February 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15133 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-28254Laravel deserialization of untrusted data vulnerabilityA deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.EPSS 1.3%9.8CVE-2022-2870Laravel deserialization of untrusted data vulnerabilityA vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deseria…EPSS 0.81%8.8CVE-2022-2886Laravel deserialization of untrusted data vulnerabilityA vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserializati…EPSS 0.70%7.5CVE-2020-24940Laravel improper input validation vulnerabilityAn issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which tab…EPSS 1.2%7.5CVE-2020-24941Laravel incorrect authorization vulnerabilityAn issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests wi…EPSS 1.1%7.5CVE-2017-16894Laravel .env file exposure leaks sensitive credentialsLaravel framework through 5.5.21 writes the .env file without restricting its permissions via the writeNewEnvironmentFileWith function in KeyGenerate…EPSS 87%analysed6.1CVE-2017-9303Laravel improper input validation vulnerabilityLaravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to condu…EPSS 0.96%5.9CVE-2017-14775Laravel information exposure vulnerabilityLaravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2018-15133), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.