CVE-2026-102279

low

Description

Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixed in versions 12.69.0 and 13.30.0.

References

https://github.com/laravel/framework/security/advisories/GHSA-jh5r-qr3c-85q8

https://github.com/laravel/framework/releases/tag/v13.30.0

https://github.com/laravel/framework/releases/tag/v12.69.0

https://github.com/laravel/framework/pull/61381

https://github.com/laravel/framework/commit/b495ca2ec4e15a977e8700328bf13e8a79f29d12

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88508

Details

Source: Mitre, NVD

Published: 2026-09-28

Updated: 2026-09-30

Risk Information

CVSS v2

Base Score: 2.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 3.1

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Severity: Low

EPSS

EPSS: 0.00202