Repository navigation
Urgent security release for GHSA-64j9-rg74-hqc7 (High).
Affected: Magewire 3.0.0–3.7.1. Fixed: Magewire 3.7.2.
Everyone running an affected release must upgrade promptly in every environment, including production, staging, development, local, demo, and test installations. Agencies should check all affected client projects, lockfiles, and deployment images they maintain.
This release restricts browser-callable component methods to application actions, validates event-listener targets, reserves framework lifecycle hooks, and accepts lazy loading only for a genuine placeholder. It retains the changes from 3.7.1.
For Magewire 3.x projects whose existing root constraints permit 3.7.2:
composer update magewirephp/magewire:3.7.2 --with-all-dependencies
composer show magewirephp/magewireReview the lockfile, test the application, and use the project's normal Magento deployment process. If a root-level version pin blocks the fix, update that constraint as part of the upgrade.
Hyvä Checkout 1.4.0 beta users: a coordinated 1.4.0-beta6 release will follow. Everyone currently using a 1.4.0 beta must upgrade when beta6 is available and verify that the installed Magewire dependency contains this fix. This requirement applies to every environment. Existing beta versions may pin an affected Magewire release, so a Magewire-only update may be blocked. Follow the Checkout release owner's supported upgrade instructions; beta6 is not being announced as available by this Magewire release.
Custom components that call inherited Magewire helpers or lifecycle hooks directly from the browser or event listeners may need a deliberate public application action that authorizes the operation and calls the helper internally. See UPGRADING.md.
Thank you to Alin Vlad / Otter Distribution for the responsible report and review.