CVE-2026-102279: CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in laravel framework
Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixed in versions 12.69.0 and 13.30.0.
AI Analysis
Technical Summary
Laravel framework versions prior to 12.69.0 and versions >=13.0.0 <13.30.0 contain a DOM-based cross-site scripting vulnerability in exception debug pages when APP_DEBUG is true. The vulnerability arises because user-controlled input is passed to a Tippy.js tooltip configured with allowHTML=true, enabling script injection upon tooltip hover. This flaw is tracked as CVE-2026-102279 and categorized under CWE-80 (Improper Neutralization of Script-Related HTML Tags). The vulnerability has a CVSS 3.1 base score of 3.1, indicating low severity. The issue is resolved in Laravel versions 12.69.0 and 13.30.0.
Potential Impact
This vulnerability allows an attacker to inject malicious scripts into the tooltip content on Laravel exception debug pages when APP_DEBUG is enabled. The impact is limited to low severity, with no confidentiality or availability impact, and only limited integrity impact. Exploitation requires user interaction (hovering over the tooltip) and the debug mode to be enabled, which is typically disabled in production environments.
Mitigation Recommendations
Upgrade Laravel to version 12.69.0 or later, or 13.30.0 or later, where this vulnerability is fixed. Avoid running applications with APP_DEBUG=true in production environments to prevent exposure of debug pages. Patch status is confirmed fixed in these versions.
CVE-2026-102279: CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in laravel framework
Description
Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixed in versions 12.69.0 and 13.30.0.
CVSS v3.1
Score 3.1low
Affected software
laravel
framework
pkg:github/laravel/frameworkRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Laravel framework versions prior to 12.69.0 and versions >=13.0.0 <13.30.0 contain a DOM-based cross-site scripting vulnerability in exception debug pages when APP_DEBUG is true. The vulnerability arises because user-controlled input is passed to a Tippy.js tooltip configured with allowHTML=true, enabling script injection upon tooltip hover. This flaw is tracked as CVE-2026-102279 and categorized under CWE-80 (Improper Neutralization of Script-Related HTML Tags). The vulnerability has a CVSS 3.1 base score of 3.1, indicating low severity. The issue is resolved in Laravel versions 12.69.0 and 13.30.0.
Potential Impact
This vulnerability allows an attacker to inject malicious scripts into the tooltip content on Laravel exception debug pages when APP_DEBUG is enabled. The impact is limited to low severity, with no confidentiality or availability impact, and only limited integrity impact. Exploitation requires user interaction (hovering over the tooltip) and the debug mode to be enabled, which is typically disabled in production environments.
Mitigation Recommendations
Upgrade Laravel to version 12.69.0 or later, or 13.30.0 or later, where this vulnerability is fixed. Avoid running applications with APP_DEBUG=true in production environments to prevent exposure of debug pages. Patch status is confirmed fixed in these versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-28T20:11:16.659Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abad639f7a7c54106343f70
Added to database: 09/28/2026, 21:03:53 UTC
Last enriched: 09/28/2026, 21:18:13 UTC
Last updated: 09/29/2026, 02:48:52 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.