SB2026081871 - Cross-site scripting in Livewire



SB2026081871 - Cross-site scripting in Livewire

Published: August 18, 2026

Security Bulletin ID SB2026081871
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Cross-site scripting (CVE-ID: CVE-2026-81887)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary JavaScript in the origin of an affected application.

The vulnerability exists due to cross-site scripting in client-side state handling when processing certain client-side component state. A remote attacker can induce the victim to interact with crafted content to execute arbitrary JavaScript in the origin of an affected application.

User interaction is required, and the issue does not bypass server-side authorization or grant privileges beyond those of the affected user.


Remediation

Install update from vendor's website.