High severity8.8NVD Advisory· Published Feb 1, 2024· Updated Jun 17, 2026
CVE-2024-22859
CVE-2024-22859
Description
Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. NOTE: the vendor disputes this because the 5d88731 commit fixes a usability problem (HTTP 419 status codes for legitimate client activity), not a security problem.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
livewire/livewirePackagist | >= 3.0.0, < 3.0.4 | 3.0.4 |
Affected products
3Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.