Arbitrary File Upload Affecting mckenziearts/livewire-markdown-editor package, versions <1.3


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Arbitrary File Upload vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-MCKENZIEARTSLIVEWIREMARKDOWNEDITOR-16419416
  • published5 May 2026
  • disclosed4 May 2026
  • creditUnknown

Introduced: 4 May 2026

New CVE NOT AVAILABLE CWE-434  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade mckenziearts/livewire-markdown-editor to version 1.3 or higher.

Overview

Affected versions of this package are vulnerable to Arbitrary File Upload via the updatedAttachments process. An attacker can upload arbitrary files by submitting crafted files through the upload interface, which may result in the execution of malicious scripts, phishing page hosting, or malware distribution when files are served from a public storage disk. This is only exploitable if the storage disk is publicly accessible and the upload UI is enabled.

Workaround

This vulnerability can be mitigated by disabling the upload UI on every instance of the editor by passing :show-upload="false".

CVSS Base Scores

version 4.0
version 3.1