Disclosure summary
### Impact When `APP_DEBUG=true`, attacker-controlled input is passed to a Tippy.js tooltip configured with `allowHTML: true`, enabling DOM-based XSS during mouse hover. ### Patches [#61381](https://github.com/laravel/framework/pull/61381)
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-jh5r-qr3c-85q8
Open original source · Updated Sep 29, 2026
Laravel: XSS in Debug Page Information
Source severity: LOW / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| composer | laravel/framework | < 12.69.0 | 12.69.0 |
| composer | laravel/framework | >= 13.0.0, < 13.30.0 | 13.30.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-29T14:24:25-04:00
MODIFIED 2026-09-29T14:25:03-04:00
INGESTED 2026-10-06T11:43:08-04:00