GHSA-g3hc-697w-wm82

Suggest an improvement
Source
https://github.com/advisories/GHSA-g3hc-697w-wm82
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-g3hc-697w-wm82/GHSA-g3hc-697w-wm82.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g3hc-697w-wm82
Aliases
Published
2026-09-02T14:38:58Z
Modified
2026-09-02T14:45:06Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Livewire DOM-based cross-site scripting during client-side state handling
Details

Impact

In Livewire v3 (≤ 3.8.2) and v4 (≤ 4.3.3), a vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the origin of an affected application in specific scenarios. The issue stems from how certain client-side component state is handled. This vulnerability does not affect prior major versions. Exploitation requires user interaction, but does not require authentication or prior access to the application. The issue does not bypass server-side authorisation and grants an attacker no privileges beyond those the affected user already holds.

Patches

This issue has been patched in Livewire v3.8.3 and v4.3.4. All users are strongly encouraged to upgrade to these versions or later as soon as possible.

Workarounds

There is no known workaround at this time. Users are strongly advised to upgrade to a patched version immediately.

Database specific
{
    "cwe_ids":  [
        "CWE-1321",
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-02T14:38:58Z",
    "nvd_published_at":  "2026-08-31T21:17:52Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / livewire/livewire

Package

Name
livewire/livewire
Purl
pkg:composer/livewire/livewire

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0-beta.1
Fixed
3.8.3

Affected versions

v3.*
v3.0.0-beta.1
v3.0.0-beta.2
v3.0.0-beta.3
v3.0.0-beta.4
v3.0.0-beta.5
v3.0.0-beta.6
v3.0.0-beta.7
v3.0.0-beta.8
v3.0.0-beta.9
v3.0.0-beta.10
v3.0.0-beta.11
v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.0.10
v3.1.0
v3.2.0
v3.2.1
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.3.0
v3.3.1
v3.3.2
v3.3.3
v3.3.4
v3.3.5
v3.4.0
v3.4.1
v3.4.2
v3.4.3
v3.4.4
v3.4.5
v3.4.6
v3.4.7
v3.4.8
v3.4.9
v3.4.10
v3.4.11
v3.4.12
v3.5.0
v3.5.1
v3.5.2
v3.5.3
v3.5.4
v3.5.5
v3.5.6
v3.5.7
v3.5.8
v3.5.9
v3.5.10
v3.5.11
v3.5.12
v3.5.13
v3.5.14
v3.5.15
v3.5.16
v3.5.17
v3.5.18
v3.5.19
v3.5.20
v3.6.0
v3.6.1
v3.6.2
v3.6.3
v3.6.4
v3.7.0-beta.1
v3.7.0-beta.2
v3.7.0
v3.7.1
v3.7.2
v3.7.3
v3.7.4
v3.7.5
v3.7.6
v3.7.7
v3.7.8
v3.7.9
v3.7.10
v3.7.11
v3.7.12
v3.7.13
v3.7.14-beta.1
v3.7.14
v3.7.15
v3.8.0
v3.8.1
v3.8.2

Database specific

last_known_affected_version_range
"<= 3.8.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-g3hc-697w-wm82/GHSA-g3hc-697w-wm82.json"

Packagist / livewire/livewire

Package

Name
livewire/livewire
Purl
pkg:composer/livewire/livewire

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0-beta.1
Fixed
4.3.4

Affected versions

v4.*
v4.0.0-beta.1
v4.0.0-beta.2
v4.0.0-beta.3
v4.0.0-beta.4
v4.0.0-beta.5
v4.0.0-beta.6
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4-beta.2
v4.2.4
v4.3.0
v4.3.1
v4.3.2
v4.3.3

Database specific

last_known_affected_version_range
"<= 4.3.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-g3hc-697w-wm82/GHSA-g3hc-697w-wm82.json"