mediumVulnerability

CVE-2026-81887

### Impact In Livewire v3 (≤ 3.8.2) and v4 (≤ 4.3.3), a vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the origin of an affected application in specific scenarios. The issue stems from how certain client-side component state is handled. This vulnerability does not affect prior major versions. Exploitation requires user interaction, but does not require authentication or prior access to the application. The issue does not bypass server-side authorisation and grants an attacker no privileges beyond those the affected user already holds. ### Patches This issue has been patched in Livewire v3.8.3 and v4.3.4. All users are strongly encouraged to upgrade to these versions or later as soon as possible. ### Workarounds There is no known workaround at this time. Users are strongly advised to upgrade to a patched version immediately.

Properties

ghsa_id
GHSA-g3hc-697w-wm82
severity
medium
summary
Livewire DOM-based cross-site scripting during client-side state handling
cve_id
CVE-2026-81887
is_ghsa_only
false
ghsa_published
2026-09-02T14:38:58Z
source_url
https://github.com/advisories/GHSA-g3hc-697w-wm82
ghsa_updated
2026-09-02T14:38:59Z

Related Entities (5)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/livewire/livewire

AFFECTS (1)

[Software]composer/livewire/livewire

HAS_WEAKNESS (2)

[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81887 — Ninja Signal Threat Intelligence | Ninja Signal