CVE-2021-3129
KEV RANSOMWARECRITICAL 9.8EPSS 99.9%
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 99.94% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2023-09-18, used in ransomware campaigns
- Nuclei
- critical
- Published
- 2021-01-12
- Updated
- 2025-10-21
Proof-of-concept exploits (36)
- http://packetstormsecurity.com/files/162094/Ignition-2.5.1-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/165999/Ignition-Remote-Code-Execution.html
- 0nion1/CVE-2021-31296★ · 2022-10-11
- 0x0d3ad/CVE-2021-312910★ · 2024-10-05
- 1111one/laravel-CVE-2021-3129-EXP1★ · 2021-07-22
- Axianke/CVE-2021-31295★ · 2024-01-15
- FunPhishing/Laravel-8.4.2-rce-CVE-2021-31292★ · 2021-02-14
- GodOfServer/CVE-2021-31290★ · 2024-10-31
- Prabesh01/hoh40★ · 2024-12-04
- SNCKER/CVE-2021-3129135★ · 2021-01-24
- SecPros-Team/laravel-CVE-2021-3129-EXP78★ · 2021-01-25
- Y0s9/CVE-2021-31290★ · 2021-02-21
- Zoo1sondv/CVE-2021-31290★ · 2023-06-03
- ajisai-babu/CVE-2021-3129-exp13★ · 2023-03-04
- ambionics/laravel-exploits289★ · 2021-01-29
- aurelien-vilminot/ENSIMAG_EXPLOIT_CVE2_3A0★ · 2023-02-20
- casagency/metasploit-CVE0★ · 2022-01-24
- cc3305/CVE-2021-31290★ · 2024-07-27
- crisprss/Laravel_CVE-2021-3129_EXP18★ · 2021-01-27
- cuongtop4598/CVE-2021-3129-Script7★ · 2022-04-08
- hupe1980/CVE-2021-31290★ · 2022-09-30
- idea-oss/laravel-CVE-2021-3129-EXP1★ · 2021-07-22
- joshuavanderpoll/CVE-2021-3129153★ · 2026-05-21
- keyuan15/CVE-2021-31291★ · 2023-03-11
- knqyf263/CVE-2021-312912★ · 2021-10-09
- lukwagoasuman/CVE-2021-3129---Laravel-RCE1★ · 2025-01-30
- miko550/CVE-2021-31290★ · 2023-07-26
- nth347/CVE-2021-3129_exploit69★ · 2021-03-07
- piperpwn/CVE-2021-3129-0★ · 2024-07-16
- piperpwn/CVE-2021-3129-piperpwn0★ · 2024-07-16
- shadowabi/Laravel-CVE-2021-31295★ · 2022-09-29
- withmasday/CVE-2021-31292★ · 2023-07-27
- wmasday/CVE-2021-31292★ · 2023-07-27
- zhzyker/CVE-2021-3129163★ · 2021-12-14
- Giangdurian/CVE-2021-3129
- theNareshofficial/CVE-2021-3129-Lab
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (1)
Vulhub environments (1)
Exploit collections (3)
- chaitin/xray/blob/master/pocs/laravel-cve-2021-3129.yml
- tzwlhack/Vulnerability/blob/main/Laravel%20%3C%3D%20V8.4.2%20Debug%E6%A8%A1%E5%BC%8F%E8%B…
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2021/CVE-2021-3129.yaml