CVE-2024-22859: Laravel Livewire

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. NOTE: the vendor disputes this because the 5d88731 commit fixes a usability problem (HTTP 419 status codes for legitimate client activity), not a security problem.

Affected products

  • Laravel Livewire: before 3.0.4 (fixed in 3.0.4)

Published 2024-02-01. Last modified 2026-06-17.