GHSA-gxxh-8vcj-w2mh

Suggest an improvement
Source
https://github.com/advisories/GHSA-gxxh-8vcj-w2mh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-gxxh-8vcj-w2mh/GHSA-gxxh-8vcj-w2mh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gxxh-8vcj-w2mh
Published
2026-05-04T22:11:05Z
Modified
2026-05-05T16:13:01Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N CVSS Calculator
Summary
livewire-markdown-editor has arbitrary file upload that allows stored XSS via attachment handler
Details

Impact

All versions of mckenziearts/livewire-markdown-editor prior to v1.3 contain a critical arbitrary file upload vulnerability in the MarkdownEditor::updatedAttachments() Livewire handler. The handler calls $file->store() with no server-side validation of MIME type, extension, or file content.

Any authenticated user with access to a page embedding <livewire:markdown-editor> can upload files of any type (.html, .svg, .js, .php, .exe, etc.) to the disk configured by livewire-markdown-editor.disk. When that disk is a public cloud bucket (S3, DigitalOcean Spaces, Cloudflare R2, Scaleway Object Storage — the common configuration when FILESYSTEM_DISK points to such a disk), uploaded files are served publicly with a guessed Content-Type header.

The consequences include:

  • Stored XSS on the storage domain via uploaded .html or .svg files
  • Phishing page hosting on the application's own storage domain (trust laundering)
  • Malware distribution from a domain users associate with the application
  • Markdown injection in the editor output via crafted filenames (the client-supplied getClientOriginalName() value was inserted verbatim into the markdown)

A real-world exploitation of this vulnerability was observed in production on a community platform using this package.

Patches

Upgrade to v1.3 or later.

Workarounds

If developers cannot upgrade immediately, disable the upload UI on every instance of the editor by passing :show-upload="false":

  <livewire:markdown-editor wire:model="content" :show-upload="false" />

This hides the file input and prevents the vulnerable code path from being reached.

Resources

Database specific
{
    "cwe_ids":  [
        "CWE-434",
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-04T22:11:05Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Packagist / mckenziearts/livewire-markdown-editor

Package

Name
mckenziearts/livewire-markdown-editor
Purl
pkg:composer/mckenziearts/livewire-markdown-editor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3

Affected versions

v1.*
v1.0
v1.0.1
v1.1
v1.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-gxxh-8vcj-w2mh/GHSA-gxxh-8vcj-w2mh.json"