Laravel: XSS in Debug Page Information
Package
Affected versions
< 12.69.0
>= 13.0.0, < 13.30.0
Patched versions
12.69.0
13.30.0
Description
Published by the National Vulnerability Database
Sep 28, 2026
Published to the GitHub Advisory Database
Sep 29, 2026
Reviewed
Sep 29, 2026
Last updated
Sep 29, 2026
Impact
When
APP_DEBUG=true, attacker-controlled input is passed to a Tippy.js tooltip configured withallowHTML: true, enabling DOM-based XSS during mouse hover.Patches
#61381
References