GHSA-jh5r-qr3c-85q8LowCVSS 3.1
Laravel: XSS in Debug Page Information
🔗 CVE IDs covered (1)
📋 Description
Impact
When APP_DEBUG=true, attacker-controlled input is passed to a Tippy.js tooltip configured with allowHTML: true, enabling DOM-based XSS during mouse hover.
Patches
🎯 Affected products2
- composer/laravel/framework:< 12.69.0
- composer/laravel/framework:>= 13.0.0, < 13.30.0
🔗 References (7)
- https://github.com/laravel/framework/security/advisories/GHSA-jh5r-qr3c-85q8
- https://nvd.nist.gov/vuln/detail/CVE-2026-102279
- https://github.com/laravel/framework/pull/61381
- https://github.com/laravel/framework/commit/b495ca2ec4e15a977e8700328bf13e8a79f29d12
- https://github.com/laravel/framework/releases/tag/v12.69.0
- https://github.com/laravel/framework/releases/tag/v13.30.0
- https://github.com/advisories/GHSA-jh5r-qr3c-85q8