THREAT OPS › Threat News › [GHSA] GHSA-g3hc-697w-wm82 (medium) — Livewire DOM-based cross-site scripting during client-side state handling
[GHSA] GHSA-g3hc-697w-wm82 (medium) — Livewire DOM-based cross-site scripting during client-side state handling
GHSA-g3hc-697w-wm82 Severity: medium CVE: CVE-2026-81887
Livewire DOM-based cross-site scripting during client-side state handling
### Impact In Livewire v3 (≤ 3.8.2) and v4 (≤ 4.3.3), a vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the origin of an affected application in specific scenarios. The issue stems from how certain client-side component state is hand
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-81887cve
Original source: https://github.com/advisories/GHSA-g3hc-697w-wm82