BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//talk//F9XSN9
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251021T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:CVE-2025-54068 : Deep dive into Livewire\, from weak typing to pre
 -authenticated remote command execution - Rémi Matasse
DTSTART;TZID=Europe/Luxembourg:20261021T144500
DTEND;TZID=Europe/Luxembourg:20261021T151500
DTSTAMP:20261009T054100Z
UID:pretalx-hack-lu-2026-F9XSN9@pretalx.com
DESCRIPTION:CVE-2025-54068 exposed a critical vulnerability in Livewire\, 
 a popular full-stack framework for Laravel\, enabling pre-authenticated re
 mote command execution (RCE) by exploiting PHP’s weak typing and Livewir
 e’s hydration mechanism. According to GitHub\, Livewire was downloaded m
 ore than 85 million times\, making it one of the most used Laravel depende
 ncy ever.\n\nTraditionally\, Livewire protects its state with a checksum s
 igned by the application’s APP_KEY. However\, this vulnerability allowed
  attackers to bypass the APP_KEY requirement entirely by smuggling synthes
 izers through the updates mechanism\, effectively breaking the state synch
 ronization between server and browser.\n\nThe root cause lies in Livewire
 ’s component property update hydration process\, where recursive calls a
 nd improper context preservation enabled malicious payload injection. Expl
 oitation required only the target application’s URL\, making it accessib
 le to unauthenticated attackers. The vulnerability affected Livewire versi
 ons from 3.0.0-beta.1 up to 3.6.3\, and was patched in version 3.6.4.\n\nT
 his talk will detail the technical chain from weak typing to RCE\, demonst
 rate the exploit process\, discuss the hardening measures implemented by L
 ivewire to prevent similar issues in the future and more especially\, show
  the consequences being the publication of the associated proof of concept
  during the end of last year.
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2026/talk/F9XSN9/
END:VEVENT
END:VCALENDAR
