DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-102279: CVE-2026-102279: DOM-based Cross-Site Scripting in Laravel Exception Debug Page via Tippy.js

CVE-2026-102279: DOM-based Cross-Site Scripting in Laravel Exception Debug Page via Tippy.js

Vulnerability ID: CVE-2026-102279
CVSS Score: 3.1
Published: 2026-09-29

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Laravel exception debug page rendering pipeline when APP_DEBUG=true is active. This flaw allows an attacker to execute arbitrary client-side JavaScript in the security context of an authenticated user's session when they hover over interactive code-trace tooltips handled by Tippy.js.

TL;DR

A DOM-based Cross-Site Scripting (XSS) flaw inside the Laravel framework exception renderer allows remote code execution in administrative sessions. The flaw triggers when debugging mode is active and a user hovers over interactive tooltips managed by Tippy.js with allowHTML enabled.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-80
  • Attack Vector: Network
  • CVSS Severity Score: 3.1 (Low)
  • EPSS Score: 0.00202 (Percentile: 9.02%)
  • Exploit Status: Proof of Concept
  • CISA KEV Status: Not Listed

Affected Systems

  • Laravel applications running versions < 12.69.0 with active debug configurations
  • Laravel applications running versions >= 13.0.0 and < 13.30.0 with active debug configurations
  • laravel/framework: < 12.69.0 (Fixed in: 12.69.0)
  • laravel/framework: >= 13.0.0, < 13.30.0 (Fixed in: 13.30.0)

Code Analysis

Commit: b495ca2

Fix potential DOM-XSS on Tippy.js tooltip interaction within exception renderer layout profiles.

Mitigation Strategies

  • Disable debugging mode by setting APP_DEBUG=false in environment configuration files across all staging and production instances.
  • Limit network exposure of administrative exception reports using IP blocklisting or intranet-only access policies.
  • Enforce content security policies (CSP) that restrict dynamic HTML rendering tools from running inline script vectors.

Remediation Steps:

  1. Open the project's root directory and check current framework versions in composer.json.
  2. Run 'composer update laravel/framework' to obtain patched libraries.
  3. Verify the installed package version is 12.69.0, 13.30.0, or newer.
  4. Inspect configuration settings to ensure production systems use APP_DEBUG=false.

References


Read the full report for CVE-2026-102279 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)