{"id":"GHSA-gxxh-8vcj-w2mh","summary":"livewire-markdown-editor has arbitrary file upload that allows stored XSS via attachment handler","details":"### Impact\nAll versions of `mckenziearts/livewire-markdown-editor` prior to **v1.3** contain a critical arbitrary file upload vulnerability in the `MarkdownEditor::updatedAttachments()` Livewire handler. The handler calls `$file-\u003estore()` with no server-side validation of MIME type, extension, or file content.\n\nAny authenticated user with access to a page embedding `\u003clivewire:markdown-editor\u003e` can upload files of any type (`.html`, `.svg`, `.js`, `.php`, `.exe`, etc.) to the disk configured by `livewire-markdown-editor.disk`. When that disk is a public cloud bucket (S3, DigitalOcean Spaces, Cloudflare R2, Scaleway Object Storage — the common configuration when `FILESYSTEM_DISK` points to such a disk), uploaded files are served publicly with a guessed `Content-Type` header.\n\nThe consequences include:\n\n- **Stored XSS** on the storage domain via uploaded `.html` or `.svg` files\n- **Phishing page hosting** on the application's own storage domain (trust laundering)\n- **Malware distribution** from a domain users associate with the application\n- **Markdown injection** in the editor output via crafted filenames (the client-supplied `getClientOriginalName()` value was inserted verbatim into the markdown)\n\nA real-world exploitation of this vulnerability was observed in production on a community platform using this package.\n\n### Patches\n\nUpgrade to **v1.3** or later.\n\n### Workarounds\n\nIf developers cannot upgrade immediately, disable the upload UI on every instance of the editor by passing `:show-upload=\"false\"`:\n\n```blade\n  \u003clivewire:markdown-editor wire:model=\"content\" :show-upload=\"false\" /\u003e\n```\n\nThis hides the file input and prevents the vulnerable code path from being reached.\n\n### Resources\n\n- Patch commit: https://github.com/mckenziearts/livewire-markdown-editor/pull/12\n- Release: https://github.com/mckenziearts/livewire-markdown-editor/releases/tag/v1.3\n- CWE-434: https://cwe.mitre.org/data/definitions/434.html\n- CWE-79: https://cwe.mitre.org/data/definitions/79.html","modified":"2026-05-05T16:13:01.980844Z","published":"2026-05-04T22:11:05Z","database_specific":{"github_reviewed_at":"2026-05-04T22:11:05Z","nvd_published_at":null,"cwe_ids":["CWE-434","CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/mckenziearts/livewire-markdown-editor/security/advisories/GHSA-gxxh-8vcj-w2mh"},{"type":"WEB","url":"https://github.com/mckenziearts/livewire-markdown-editor/commit/1e60eaa5781e89704e112425f832774be85cd71f"},{"type":"PACKAGE","url":"https://github.com/mckenziearts/livewire-markdown-editor"},{"type":"WEB","url":"https://github.com/mckenziearts/livewire-markdown-editor/releases/tag/v1.3"}],"affected":[{"package":{"name":"mckenziearts/livewire-markdown-editor","ecosystem":"Packagist","purl":"pkg:composer/mckenziearts/livewire-markdown-editor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3"}]}],"versions":["v1.0","v1.0.1","v1.1","v1.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-gxxh-8vcj-w2mh/GHSA-gxxh-8vcj-w2mh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"}]}