Summary
Livewire DOM-based cross-site scripting during client-side state handling
Advisory details
Impact
In Livewire v3 (≤ 3.8.2) and v4 (≤ 4.3.3), a vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the origin of an affected application in specific scenarios. The issue stems from how certain client-side component state is handled. This vulnerability does not affect prior major versions. Exploitation requires user interaction, but does not require authentication or prior access to the application. The issue does not bypass server-side authorisation and grants an attacker no privileges beyond those the affected user already holds.
Patches
This issue has been patched in Livewire v3.8.3 and v4.3.4. All users are strongly encouraged to upgrade to these versions or later as soon as possible.
Workarounds
There is no known workaround at this time. Users are strongly advised to upgrade to a patched version immediately.
References
- https://github.com/advisories/GHSA-g3hc-697w-wm82
- https://github.com/livewire/livewire/security/advisories/GHSA-g3hc-697w-wm82
- https://nvd.nist.gov/vuln/detail/CVE-2026-81887
- https://github.com/livewire/livewire/pull/10467
- https://github.com/livewire/livewire/commit/11ebe646f7e81dde2d714815da8b3019d058561e
- https://github.com/livewire/livewire/releases/tag/v3.8.3
- https://github.com/livewire/livewire/releases/tag/v4.3.4
Related vulnerabilities
All Supply chain →- MEDIUMGHSA-cp6q-959q-f8rh
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes
- HIGHCVE-2026-63376
toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization
- MEDIUMCVE-2026-63670
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
- MEDIUMCVE-2026-73295
Material for MkDocs: DOM XSS in search suggestions via query parameter
- HIGHCVE-2026-82404
TOON: Prototype pollution when decoding untrusted TOON input
- HIGHGHSA-99rq-75j6-5j9f
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass