Cross-Site Scripting Vulnerability in Laravel Framework
CVE-2026-102279

3.1LOW

Key Information:

Vendor

Laravel

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-102279?

The Laravel framework contains a vulnerability where exception debug pages reveal information when the APP_DEBUG setting is enabled. If the application allows HTML in tooltips, an attacker can inject malicious scripts. This occurs when users hover over Tippy.js tooltips, allowing the execution of arbitrary JavaScript. This issue has been addressed in versions 12.69.0 and 13.30.0.

Affected Version(s)

framework < 12.69.0 < 12.69.0

framework >= 13.0.0, < 13.30.0 < 13.0.0, 13.30.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.