Junglewise Threat Intelligence

CVE-2026-55409: Filament RichEditor stored XSS in disabled fields

CVE-2026-55409 · Severity: high · CVSS 7.6 · Published 2026-06-22

Vendors: Packagist.

Executive brief

Filament is a popular set of components used to build administrative interfaces for Laravel web applications. A security flaw in the RichEditor component allowed malicious code to be executed in the browser of users viewing certain forms. This could lead to unauthorized access to user sessions or sensitive data if an attacker manages to save malicious content into a field that is later displayed in a disabled state.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Filament v3's RichEditor component. When the field is set to a 'disabled' state, it renders the raw underlying state without performing HTML sanitization. If an attacker can populate the field's state with malicious HTML or JavaScript (e.g., through a separate input vector or direct database manipulation), the payload will execute in the context of any user viewing the form. This issue is specific to the v3 branch and is addressed in version 3.3.53; Filament v4 is not affected due to a different rendering mechanism.

Affected products

  • filamentphp filament/forms >= 3.0.0, < 3.3.53

Timeline

  • 2026-06-17: advisory: GitHub security advisory published by maintainers
  • 2026-06-22: disclosed: CVE published to NVD
  • 2026-06-22: patched: Fix released in version 3.3.53

References