GHSA-g3hc-697w-wm82: XSS
Impact In Livewire v3 (≤ 3.8.2) and v4 (≤ 4.3.3), a vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the origin of an affected application in specific scenarios. The issue stems from how certain client-side component state is handled. This vulnerability does not affect prior major versions. Exploitation requires user interaction, but does not require authentication or prior access to the application. The issue does not bypass server-side authorisation and grants an attacker no privileges beyond those the affected user already holds.
Patches This issue has been patched in Livewire v3.8.3 and v4.3.4. All users are strongly encouraged to upgrade to these versions or later as soon as possible.
Workarounds There is no known workaround at this time. Users are strongly advised to upgrade to a patched version immediately.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/livewire/livewireto a version that resolves this vulnerability.Fixed in 4.3.4 - Upgrade
Upgrade
composer/livewire/livewireto a version that resolves this vulnerability.Fixed in 3.8.3 - Upgrade
Upgrade
Livewireto a version that resolves this vulnerability.Fixed in 3.8.3 - Upgrade
Upgrade
Livewireto a version that resolves this vulnerability.Fixed in 4.3.4
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments use Livewire v3.8.2 or earlier within the v3 major release, or Livewire v4.3.3 or earlier within the v4 major release. Prior major versions are not affected.
What does an attacker need to exploit this issue?
An attacker does not need authentication or prior access to the application, but exploitation requires interaction from a user. Successful exploitation allows arbitrary JavaScript to run in the affected application's origin.
Does exploitation provide server-side privileges or bypass authorization?
No. The issue does not bypass server-side authorization and does not grant privileges beyond those already held by the affected user.
What should teams do if they are running an affected version?
Upgrade Livewire to v3.8.3 or later, or v4.3.4 or later, depending on the major version in use. No workaround is known if patching cannot be performed immediately.