CVE-2021-3129
CVE-2021-3129 — Laravel Ignition File Upload Vulnerability
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
Published Updated Sources: NVD, Laravel (CNA), CISA, FIRST EPSS, GitHub, Exploit-DB, SOCRadar CTI
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Confirmed
CISA KEV, listed Sep 18, 2023
EPSS
100%
top of FIRST's scoreset
CVSS base
9.8
critical · 2 sources
CISA SSVC assessment
Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.
Exploitation
Active
none · proof-of-concept · active
Automatable
Yes
can an attacker script all four kill-chain steps
Technical impact
Total
partial · total control of the vulnerable component
Remediation
The vendor's own words where we have them.
Upgrade Ignition to a fixed release. Apply vendor patches per advisory and restrict external exposure of the affected component until patched.
CISA required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Federal deadline Oct 9, 2023 — passed 1,075 days ago
First 24 hours
Ordered from the record's own fields — exposure first, because you cannot patch what you have not found.
- Identify exposed assets running affected vendor/product/version combinations.
- Treat as emergency remediation because CISA KEV status is present.
- Search available logs for exploit probes, errors, authentication anomalies, or suspicious child processes matching the vulnerability class.
Affected scope
Vendor, product and version as the advisories word them.
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Laravel | Ignition | — | Vulnerable |
Attack characteristics
The CVSS vector, decoded. It describes the attack, not your exposure to it.
Availability
High
Confidentiality
High
Integrity
High
Scope
Unchanged
Attack Complexity
Low
Attack Vector
Network
Privileges Req
None
User Interaction
None
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 9.8 | CVSS 3.1 | critical | 3.9 | 5.9 | NVD, CNA |
| 7.5 | CVSS 2.0 | high | 10 | 6.4 | NVD |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV details
CISA lists a CVE here once it has evidence of exploitation against real targets.
Listed
Sep 18, 2023
Federal deadline
Oct 9, 2023
passed 1,075 days ago
Ransomware use
Known
CISA records ransomware use only for campaigns it has confirmed, so “Unknown” means unrecorded, not ruled out. The deadline binds US federal agencies; for everyone else it is a date to argue against.
Public exploit
Capability, not use: code existing is a different claim from anyone running it.
Repositories
175
1 of the 5 sampled are weaponized
Exploit entries
38
Exploit-DB and CTI exploit indexes
Social mentions
Posts naming this CVE. Attention, not evidence of exploitation — it spikes on disclosure and decays whether or not anything is exploited.
A tool for finding errors in your code becomes the error. We reproduced the public code injection CVE-2021-3129 in Laravel Ignition's debug functionality. Exploit built, patch verified to close.
@vulnresearchlab· Aug 16, 2026
Cytellite recent detection targeting CVE-2021-3129 — Tamatiya EOOD Visit -- https://t.co/eyaTKj04Mg #Loginsoft #Cytellite #Cybersecurity #CVE20213129 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/YVJELUc5nz
@Loginsoft_Intel· Mar 1, 2026
Cytellite recent detection targeting CVE-2021-3129 — Tamatiya EOOD Visit -- https://t.co/eyaTKj04Mg #Loginsoft #Cytellite #Cybersecurity #CVE20213129 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/8olzN03ncg
@Loginsoft_Intel· Mar 1, 2026
🔒 SECURITY LESSON #8: Your website leaks tech stack? Hackers LOVE it! 😈 Laravel 8.0 exposed → CVE-2021-3129 RCE exploit .git folders, error stack traces, headers = GOLDMINE for attacks Kenyan gov site: 2.3M records stolen in 2023 FIX: Hide versions, custom errors, block .env!
@byteshieldke· Jan 10, 2026
Detection
Read off the CVSS vector and the weakness class. Starting points, not rules we have tested.
- Prioritize edge telemetry for network-reachable Ignition.
- Monitor for scanner or exploit-pattern traffic after 213 public PoC repositories were reported.
Groups associated with this CVE
Groups reported in connection with this vulnerability. A reported association, not a confirmed observation of that group using it — and not scoped to any sector or campaign.
- ip80.83.124.15036
Kaspersky Public Requests · Nov 4, 2023
- hash334e32e7eea638089a7259c594d87db965
SOCRadar Threat Exchange Services · Jul 11, 2026
- hashb05579c5144602216ce0787cf1161bb60a67e9e265
SOCRadar Threat Exchange Services · Jul 11, 2026
- hash49152:deurfqriidw7kamngrs7qibb8gdcdomsu+zomwghvls3uewtzkcfz6gc7ppyziil:c+vq5pmgcpv+
SOCRadar Threat Exchange Services · Jun 29, 2026
Timeline
What happened to this CVE, newest first — with the readings a source repeats on a schedule counted underneath rather than listed.
- 2026
Cve is exploited theNareshofficial/CVE-2021-3129-Lab
Aug 8, 2026 · SOCRadar CTI
Added · CVSS 3.1 9.8 (AV:N)
Jun 17, 2026 · NVD
- 2025
Bulletin released on NIST.
Oct 16, 2025 · SOCRadar CTI
Bulletin released on NIST.
Oct 16, 2025 · SOCRadar CTI
Cve is exploited Prabesh01/hoh4
Apr 14, 2025 · SOCRadar CTI
Bulletin released on NIST.
Mar 7, 2025 · SOCRadar CTI
CVE is exploited. "lukwagoasuman/CVE-2021-3129---Laravel-RCE"
Jan 30, 2025 · SOCRadar CTI
- 2024
CVE is exploited. "0x0d3ad/CVE-2021-3129"
Sep 29, 2024 · SOCRadar CTI
- 2023
Added to CISA KEV catalog
Sep 18, 2023 · CISA
- 2021
Added · webapps entry: Laravel 8.4.2 debug mode - Remote code execution
Jan 14, 2021 · Exploit-DB
Initial · CVE published
Jan 12, 2021 · NVD
Source activity
Readings a source repeats on a schedule, counted rather than listed.
- 10×TweetsMar 6, 2025 – Aug 17, 2026 · SOCRadar CTI
- 7×Github ReposJul 16, 2024 – Aug 7, 2026 · SOCRadar CTI
- 2×SVRS was changedMar 2, 2026 – Aug 8, 2026 · SOCRadar CTI
- 1×CVE appeared in the Cve Trends.Jul 20, 2026 · SOCRadar CTI
- 1×1 time mentioned on 1 Telegram channelJul 9, 2025 · SOCRadar CTI
- 1×CVE modified by NIST: CVSS v2 metrics updated.Mar 7, 2025 · SOCRadar CTI
References
8 on the record
- packetstormsecurity.com/files/162094/Ignition-2.5.1-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry, NIST, GITHUB
- packetstormsecurity.com/files/165999/Ignition-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry, GITHUB, NIST
- github.com/facade/ignition/pull/334
Patch, Third Party Advisory, NIST, MITRE_REFERENCES
- www.ambionics.io/blog/laravel-debug-rce
Exploit, Third Party Advisory, NIST, MITRE_REFERENCES
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3129
US Government Resource
- www.exploit-db.com/exploits/49424
Vendor Advisory
- github.com/facade/ignition/releases/tag/2.5.2
Vendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2021-3129
Vendor Advisory
Coverage
1 story from the feeds we poll
Elsewhere on this site
- Laravelevery CVE for this vendor
- September 2023what else CISA listed
- Unclassifiedsame class
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- Only the 4 indicator(s) reported for this CVE are available; no packet-level or host-forensic artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.
Answered from this record1
What should defenders know first?
CVE-2021-3129 is Laravel Ignition File Upload Vulnerability, a critical vulnerability affecting Ignition from Laravel. The current evidence lists it in CISA KEV, and the exploit status is: Yes: CISA KEV signal present. Public exploit evidence is: 213 public PoC repositories reported; 1 marked weaponized in current dataset. The affected-version evidence is listed in the key facts and affected products tables. Defenders should first verify whether exposed or business-critical assets run those versions, then apply vendor patches or mitigations, restrict reachable attack surface, and preserve logs for detection review. CVSS 9.8 describes technical severity, while EPSS 100% helps estimate near-term exploit likelihood; neither replaces asset context. Unknown fields should remain explicit in tickets, and threat actor, IOC, victimology, or payload claims should not be added unless a cited source supports them. Monitor CISA KEV, vendor advisories, NVD changes, public PoC repositories, and internal telemetry for update triggers.
