Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
https://www.infosecurity-magazine.com/news/php-servers-and-iot-devices-cyber/
https://thehackernews.com/2025/10/experts-reports-sharp-increase-in.html
https://sysdig.com/blog/llmjacking-stolen-cloud-credentials-used-in-new-ai-attack/
https://veriti.ai/blog/vulnerable-villain-when-hackers-get-hacked/
https://github.com/Giangdurian/CVE-2021-3129
https://github.com/Athology0000/cve-lab
https://github.com/theNareshofficial/CVE-2021-3129-Lab
https://github.com/hermestoola/bb-hunter-pro
https://github.com/yashtony/network-vulnerability-scanner
https://github.com/codebyebrahim/laravel-vuln-checker
https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks
https://github.com/lukwagoasuman/CVE-2021-3129---Laravel-RCE
https://github.com/Prabesh01/hoh4
https://github.com/GodOfServer/CVE-2021-3129
https://github.com/piperpwn/CVE-2021-3129-
https://github.com/Axianke/CVE-2021-3129
https://github.com/r3volved/CVEAggregate
https://github.com/withmasday/CVE-2021-3129
https://github.com/miko550/CVE-2021-3129
https://github.com/keyuan15/CVE-2021-3129
https://github.com/aurelien-vilminot/ENSIMAG_EXPLOIT_CVE2_3A
https://github.com/MadExploits/Laravel-debug-Checker
https://github.com/0nion1/CVE-2021-3129
https://github.com/advisories/GHSA-4qwp-7c67-jmcc
https://github.com/simonlee-hello/CVE-2021-3129
https://github.com/zhzyker/CVE-2021-3129
https://github.com/nth347/CVE-2021-3129_exploit
https://github.com/ambionics/laravel-exploits
https://github.com/XuCcc/VulEnv
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3129
https://www.ambionics.io/blog/laravel-debug-rce
http://packetstormsecurity.com/files/165999/Ignition-Remote-Code-Execution.html
http://packetstormsecurity.com/files/162094/Ignition-2.5.1-Remote-Code-Execution.html