GHSA-g3hc-697w-wm82: XSS

Published Sep 2, 2026
·
Updated

Impact In Livewire v3 (≤ 3.8.2) and v4 (≤ 4.3.3), a vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the origin of an affected application in specific scenarios. The issue stems from how certain client-side component state is handled. This vulnerability does not affect prior major versions. Exploitation requires user interaction, but does not require authentication or prior access to the application. The issue does not bypass server-side authorisation and grants an attacker no privileges beyond those the affected user already holds.

Patches This issue has been patched in Livewire v3.8.3 and v4.3.4. All users are strongly encouraged to upgrade to these versions or later as soon as possible.

Workarounds There is no known workaround at this time. Users are strongly advised to upgrade to a patched version immediately.

Affected Software

2 affected componentsFixes available
composer/livewire/livewire>=4.0.0-beta.1<=4.3.3
4.3.4
composer/livewire/livewire>=3.0.0-beta.1<=3.8.2
3.8.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/livewire/livewire to a version that resolves this vulnerability.

    Fixed in 4.3.4
  2. Upgrade

    Upgrade composer/livewire/livewire to a version that resolves this vulnerability.

    Fixed in 3.8.3
  3. Upgrade

    Upgrade Livewire to a version that resolves this vulnerability.

    Fixed in 3.8.3
  4. Upgrade

    Upgrade Livewire to a version that resolves this vulnerability.

    Fixed in 4.3.4

Event History

Sep 2, 2026
Advisory Published
via GitHub·02:38 PM
Data Sourced
via GitHub·02:38 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected?

Affected deployments use Livewire v3.8.2 or earlier within the v3 major release, or Livewire v4.3.3 or earlier within the v4 major release. Prior major versions are not affected.

2

What does an attacker need to exploit this issue?

An attacker does not need authentication or prior access to the application, but exploitation requires interaction from a user. Successful exploitation allows arbitrary JavaScript to run in the affected application's origin.

3

Does exploitation provide server-side privileges or bypass authorization?

No. The issue does not bypass server-side authorization and does not grant privileges beyond those already held by the affected user.

4

What should teams do if they are running an affected version?

Upgrade Livewire to v3.8.3 or later, or v4.3.4 or later, depending on the major version in use. No workaround is known if patching cannot be performed immediately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203