CVE-2024-22859: Laravel Livewire
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. NOTE: the vendor disputes this because the 5d88731 commit fixes a usability problem (HTTP 419 status codes for legitimate client activity), not a security problem.
Affected products
- Laravel Livewire: before 3.0.4 (fixed in 3.0.4)
Published 2024-02-01. Last modified 2026-06-17.