Moderate severityGHSA Advisory· Published Jun 11, 2026· Updated Jun 11, 2026
Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields
CVE-2026-48067
Description
The recordSelectOptionsQuery() method may be used to scope the options available in the Select field for AttachAction and AssociateAction. However, the built-in validation rule for these fields did not apply the same scope. As a result, a user who can trigger these actions could tamper with the Livewire component's state and submit an out-of-scope value.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
filament/tablesPackagist | >= 3.0.0, < 3.3.51 | 3.3.51 |
filament/actionsPackagist | >= 4.0.0, < 4.11.4 | 4.11.4 |
filament/actionsPackagist | >= 5.0.0, < 5.6.4 | 5.6.4 |
Affected products
3- Range: >= 5.0.0, <= 5.6.3
- ghsa-coords2 versions
>= 4.0.0, < 4.11.4+ 1 more
- (no CPE)range: >= 4.0.0, < 4.11.4
- (no CPE)range: >= 3.0.0, < 3.3.51
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-7q3w-xqjw-g3crghsaADVISORY
- github.com/filamentphp/filament/releases/tag/v3.3.51ghsaWEB
- github.com/filamentphp/filament/releases/tag/v4.11.4ghsaWEB
- github.com/filamentphp/filament/releases/tag/v5.6.4ghsaWEB
- github.com/filamentphp/filament/security/advisories/GHSA-7q3w-xqjw-g3crghsaWEB
News mentions
0No linked articles in our index yet.