Vulnerability GHSA-jh5r-qr3c-85q8

Low Risk
LOW RISK
CVSS Score: 3.1
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
6 hours ago
September 29, 2026 at 06:24 PM UTC
Laravel: XSS in Debug Page Information
4.0.0-BETA2 - 12.68.0 and 13.0.0 - 13.29.0
4.0.0-BETA2 - 12.68.0 and 13.0.0 - 13.29.0

Summary

Laravel: XSS in Debug Page Information

Details

Impact

When APP_DEBUG=true, attacker-controlled input is passed to a Tippy.js tooltip configured with allowHTML: true, enabling DOM-based XSS during mouse hover.

Patches

#61381

Impacted packages

Timeline

Published
6 hours ago
September 29, 2026 at 06:24 PM UTC
Fixed (13.30.0)
28 days ago
September 01, 2026 at 01:19 PM UTC
Fixed (12.69.0)
28 days ago
September 01, 2026 at 01:24 PM UTC
Last Modified
6 hours ago
September 29, 2026 at 06:30 PM UTC