Cross-site scripting in Livewire - CVE-2026-81887

 

Cross-site scripting in Livewire - CVE-2026-81887

Published: August 18, 2026 / Updated: September 1, 2026


Vulnerability identifier: #VU144225
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-81887
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript in the origin of an affected application.

The vulnerability exists due to cross-site scripting in client-side state handling when processing certain client-side component state. A remote attacker can induce the victim to interact with crafted content to execute arbitrary JavaScript in the origin of an affected application.

User interaction is required, and the issue does not bypass server-side authorization or grant privileges beyond those of the affected user.


Affected software

Livewire

How to mitigate CVE-2026-81887

Install security update from vendor's website.

Livewire - addressed in versions 3.8.3, 4.3.4

External References

Related Security Bulletins