{"id":"CVE-2026-81887","aliases":["GHSA-g3hc-697w-wm82"],"url":"https://o3.security/vulnerability/CVE-2026-81887","summary":"Livewire DOM-based cross-site scripting during client-side state handling","details":"Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __proto__, constructor, and prototype path segments and creates inherited objects. Client-side state handlers then access effects.html, effects.js, effects.xjs, and effects.scripts without Object.prototype.hasOwnProperty.call(), allowing inherited attacker-controlled state to be treated as trusted effects. An unauthenticated attacker can craft a URL that, when opened by a user, executes arbitrary JavaScript in the affected application's origin. Exploitation requires user interaction and does not bypass server-side authorization or grant privileges beyond the affected user. This issue is fixed in versions 3.8.3 and 4.3.4.","published":"2026-08-31T20:12:15.932Z","modified":"2026-09-02T03:47:30.070074723Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"livewire/livewire","fixedVersion":"3.8.3"},{"ecosystem":"Packagist","name":"livewire/livewire","fixedVersion":"4.3.4"}],"fix":{"url":"https://github.com/livewire/livewire/commit/11ebe646f7e81dde2d714815da8b3019d058561e","label":"livewire/livewire@11ebe64"},"references":[{"type":"WEB","url":"https://github.com/livewire/livewire/releases/tag/v3.8.3"},{"type":"WEB","url":"https://github.com/livewire/livewire/releases/tag/v4.3.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81887.json"},{"type":"ADVISORY","url":"https://github.com/livewire/livewire/security/advisories/GHSA-g3hc-697w-wm82"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81887"},{"type":"FIX","url":"https://github.com/livewire/livewire/commit/11ebe646f7e81dde2d714815da8b3019d058561e"},{"type":"FIX","url":"https://github.com/livewire/livewire/pull/10467"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-02T03:47:30.070074723Z"}}