THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g3hc-697w-wm82 (medium) — Livewire DOM-based cross-site scripting during client-side state handling

[GHSA] GHSA-g3hc-697w-wm82 (medium) — Livewire DOM-based cross-site scripting during client-side state handling

medgithub_advisoriesPublished 2026-09-02

GHSA-g3hc-697w-wm82 Severity: medium CVE: CVE-2026-81887

Livewire DOM-based cross-site scripting during client-side state handling

### Impact In Livewire v3 (≤ 3.8.2) and v4 (≤ 4.3.3), a vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the origin of an affected application in specific scenarios. The issue stems from how certain client-side component state is hand

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g3hc-697w-wm82