PT-2026-102378 · Laravel+1 · Laravel+1

·

CVE-2026-102279

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Laravel versions prior to 12.69.0 Laravel versions prior to 13.30.0
Description Exception debug pages configured with APP DEBUG=true pass attacker-controlled input to a Tippy.js tooltip. Because the tooltip is configured with allowHTML set to true, it enables DOM-based cross-site scripting (XSS), a technique where a malicious script is executed in the victim's browser, when a user hovers over the tooltip.
Recommendations Update to version 12.69.0 or later. Update to version 13.30.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102279
GHSA-JH5R-QR3C-85Q8

Affected Products

Laravel
Tippy.Js