Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jh5r-qr3c-85q8 | Laravel: XSS in Debug Page Information |
Tue, 29 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Laravel
Laravel framework |
|
| Vendors & Products |
Laravel
Laravel framework |
Mon, 28 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixed in versions 12.69.0 and 13.30.0. | |
| Title | Laravel: XSS in Debug Page Information | |
| Weaknesses | CWE-80 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-29T14:44:03.594Z
Reserved: 2026-09-28T20:11:16.659Z
Link: CVE-2026-102279
Updated: 2026-09-29T14:43:59.837Z
Status : Received
Published: 2026-09-28T21:17:16.710
Modified: 2026-09-29T15:17:17.440
Link: CVE-2026-102279
No data.
OpenCVE Enrichment
Updated: 2026-09-28T23:00:07Z
Github GHSA