CVE-2026-102279: DOM-based Cross-Site Scripting in Laravel Exception Debug Page via Tippy.js
Vulnerability ID: CVE-2026-102279
CVSS Score: 3.1
Published: 2026-09-29
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Laravel exception debug page rendering pipeline when APP_DEBUG=true is active. This flaw allows an attacker to execute arbitrary client-side JavaScript in the security context of an authenticated user's session when they hover over interactive code-trace tooltips handled by Tippy.js.
TL;DR
A DOM-based Cross-Site Scripting (XSS) flaw inside the Laravel framework exception renderer allows remote code execution in administrative sessions. The flaw triggers when debugging mode is active and a user hovers over interactive tooltips managed by Tippy.js with allowHTML enabled.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-80
- Attack Vector: Network
- CVSS Severity Score: 3.1 (Low)
- EPSS Score: 0.00202 (Percentile: 9.02%)
- Exploit Status: Proof of Concept
- CISA KEV Status: Not Listed
Affected Systems
- Laravel applications running versions < 12.69.0 with active debug configurations
- Laravel applications running versions >= 13.0.0 and < 13.30.0 with active debug configurations
-
laravel/framework: < 12.69.0 (Fixed in:
12.69.0) -
laravel/framework: >= 13.0.0, < 13.30.0 (Fixed in:
13.30.0)
Code Analysis
Commit: b495ca2
Fix potential DOM-XSS on Tippy.js tooltip interaction within exception renderer layout profiles.
Mitigation Strategies
- Disable debugging mode by setting APP_DEBUG=false in environment configuration files across all staging and production instances.
- Limit network exposure of administrative exception reports using IP blocklisting or intranet-only access policies.
- Enforce content security policies (CSP) that restrict dynamic HTML rendering tools from running inline script vectors.
Remediation Steps:
- Open the project's root directory and check current framework versions in composer.json.
- Run 'composer update laravel/framework' to obtain patched libraries.
- Verify the installed package version is 12.69.0, 13.30.0, or newer.
- Inspect configuration settings to ensure production systems use APP_DEBUG=false.
References
Read the full report for CVE-2026-102279 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)