Cross-site scripting in Livewire - CVE-2026-81887
Published: August 18, 2026 / Updated: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the origin of an affected application.
The vulnerability exists due to cross-site scripting in client-side state handling when processing certain client-side component state. A remote attacker can induce the victim to interact with crafted content to execute arbitrary JavaScript in the origin of an affected application.
User interaction is required, and the issue does not bypass server-side authorization or grant privileges beyond those of the affected user.