CVE-2024-55661 - CVE House
Back to Database
Status published High CVE-2024-55661

Laravel Pulse Allows Remote Code Execution via Unprotected Query Method

Vulnerability Description

Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discovered in Laravel Pulse prior to version 1.3.1 that could allow remote code execution through the public `remember()` method in the `Laravel\Pulse\Livewire\Concerns\RemembersQueries` trait. This method is accessible via Livewire components and can be exploited to call arbitrary callables within the application. An authenticated user with access to Laravel Pulse dashboard can execute arbitrary code by calling any function or static method in which the callable is a function or static method and the callable has no parameters or no strict parameter types. The vulnerable to component is `remember(callable $query, string $key = '')` method in `Laravel\Pulse\Livewire\Concerns\RemembersQueries`, and the vulnerability affects all Pulse card components that use this trait. Version 1.3.1 contains a patch.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-55661

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

pulse
Vulnerable Versions:
< 1.3.1

Timeline

Official Publish: December 13th, 2024
Last Modified: December 13th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)