rootpwn

low · CVSS v3 3.1

CVE-2026-102279

Laravel exception debug pages with APP_DEBUG=true can expose attacker-controlled input to a Tippy.js tooltip that allows HTML, leading to DO

Overview

Laravel exception debug pages with APP_DEBUG=true can expose attacker-controlled input to a Tippy.js tooltip that allows HTML, leading to DOM-based XSS when users hover over the tooltip. The flaw exists in Laravel 12.x before 12.69.0 and 13.x before 13.30.0. It is fixed in the newer releases.

Description

Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixed in versions 12.69.0 and 13.30.0.

Impact

Defenders should be aware that attackers can inject malicious scripts into the UI of any site running a vulnerable Laravel version, compromising confidentiality, integrity, and availability of the web application and potentially the users’ browsers. The attack requires the target to have APP_DEBUG enabled and a user to hover over the tooltip.

Remediation

Upgrade Laravel to 12.69.0 or newer, or 13.30.0 or newer. If upgrading is not immediately possible, disable APP_DEBUG in production, or configure Tippy.js to set allowHTML=false and sanitize any user input before rendering.

Risk context

The CVSS v3 score is 3.1 and the severity is low, indicating a low overall risk. However, because the vulnerability is only exploitable when debug mode is enabled, the practical risk in production environments is minimal.

Affected products

  • Laravel 12.x
  • Laravel 13.x

Scores

Severity
low
CVSS v2
2.6
CVSS v3
3.1
CVSS v4
—
EPSS
—

Laravel XSS DOM Tippy.js debug low

← All CVEs