highCVSS 7.1Vulnerability

GHSA-gxxh-8vcj-w2mh

### Impact All versions of `mckenziearts/livewire-markdown-editor` prior to **v1.3** contain a critical arbitrary file upload vulnerability in the `MarkdownEditor::updatedAttachments()` Livewire handler. The handler calls `$file->store()` with no server-side validation of MIME type, extension, or file content. Any authenticated user with access to a page embedding `<livewire:markdown-editor>` can upload files of any type (`.html`, `.svg`, `.js`, `.php`, `.exe`, etc.) to the disk configured by `livewire-markdown-editor.disk`. When that disk is a public cloud bucket (S3, DigitalOcean Spaces, Cloudflare R2, Scaleway Object Storage — the common configuration when `FILESYSTEM_DISK` points to such a disk), uploaded files are served publicly with a guessed `Content-Type` header. The consequences include: - **Stored XSS** on the storage domain via uploaded `.html` or `.svg` files - **Phishing page hosting** on the application's own storage domain (trust laundering) - **Malware distribution** from a domain users associate with the application - **Markdown injection** in the editor output via crafted filenames (the client-supplied `getClientOriginalName()` value was inserted verbatim into the markdown) A real-world exploitation of this vulnerability was observed in production on a community platform using this package. ### Patches Upgrade to **v1.3** or later. ### Workarounds If developers cannot upgrade immediately, disable the upload UI on every instance of the editor by passing `:show-upload="false"`: ```blade <livewire:markdown-editor wire:model="content" :show-upload="false" /> ``` This hides the file input and prevents the vulnerable code path from being reached. ### Resources - Patch commit: https://github.com/mckenziearts/livewire-markdown-editor/pull/12 - Release: https://github.com/mckenziearts/livewire-markdown-editor/releases/tag/v1.3 - CWE-434: https://cwe.mitre.org/data/definitions/434.html - CWE-79: https://cwe.mitre.org/data/definitions/79.html

Properties

ghsa_id
GHSA-gxxh-8vcj-w2mh
summary
livewire-markdown-editor has arbitrary file upload that allows stored XSS via attachment handler
severity
high
cvss_score
7.1
cve_id
GHSA-gxxh-8vcj-w2mh
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-05-04T22:11:05Z
source_url
https://github.com/advisories/GHSA-gxxh-8vcj-w2mh
ghsa_updated
2026-05-04T22:11:07Z

Related Entities (5)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/mckenziearts/livewire-markdown-editor

AFFECTS (1)

[Software]composer/mckenziearts/livewire-markdown-editor

HAS_WEAKNESS (2)

[Weakness]Unrestricted Upload of File with Dangerous Type
[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Explore deeper with Ninja Signal's threat intelligence graph