GHSA-jh5r-qr3c-85q8LowCVSS 3.1

Laravel: XSS in Debug Page Information

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

When APP_DEBUG=true, attacker-controlled input is passed to a Tippy.js tooltip configured with allowHTML: true, enabling DOM-based XSS during mouse hover.

Patches

#61381

🎯 Affected products2

  • composer/laravel/framework:< 12.69.0
  • composer/laravel/framework:>= 13.0.0, < 13.30.0

🔗 References (7)