Laravel: XSS in Debug Page Information – CVE-2026-102279 (Low) -DC-Sep2026-2627

Listen to this Post

The vulnerability exists in Laravel’s exception debug page rendering pipeline when the application is configured with APP_DEBUG=true. Under this condition, attacker-controlled input—such as request parameters, headers, or other user-supplied data captured in the exception trace—is passed directly into a Tippy.js tooltip component. The Tippy.js tooltip is initialized with the `allowHTML: true` option, which instructs the library to interpret the tooltip content as raw HTML rather than plain text. Because the input is not sufficiently sanitized or encoded before being injected into the tooltip, an attacker can craft a malicious payload that breaks out of the intended HTML context and injects arbitrary JavaScript. When a user hovers over the affected tooltip element, the JavaScript executes in the context of the user’s session, resulting in DOM-based cross-site scripting. This flaw is classified as CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page) and is tracked as CVE-2026-102279. The vulnerability affects Laravel framework versions prior to 12.69.0 and versions greater than or equal to 13.0.0 but less than 13.30.0. The issue was patched in versions 12.69.0 and 13.30.0 via commit b495ca2, which addresses the improper handling of HTML content within the Tippy.js tooltip configuration. The CVSS score is 3.1, indicating low severity, with a network attack vector and low complexity. The exploit status is Proof of Concept (POC), and the EPSS score is 0.00202. While the vulnerability requires `APP_DEBUG=true` to be exploitable, misconfigured production environments or staging servers with debug mode enabled remain at risk. An attacker who can influence the input displayed in the debug page—for example, by sending a crafted HTTP request that triggers an exception—can deliver a payload that executes when an administrator or developer hovers over the tooltip. The tooltip is part of the interactive code-trace interface, making it likely that a user will interact with it during debugging. The patch likely involves either sanitizing the tooltip content, disabling allowHTML, or both. Organizations should upgrade to the patched versions immediately and ensure `APP_DEBUG` is set to `false` in all non-development environments.

DailyCVE Form:

Platform: Laravel
Version: <12.69.0, <13.30.0
Vulnerability: DOM XSS
Severity: Low
date: 2026-09-10

Prediction: 2026-09-30

What Undercode Say:

Check current Laravel framework version
composer show laravel/framework | grep versions
Upgrade to patched version
composer update laravel/framework
Verify APP_DEBUG setting
grep APP_DEBUG .env
// Vulnerable configuration in exception renderer (conceptual)
tippy(element, [
'allowHTML' => true, // <-- allows raw HTML injection
'content' => $attackerControlledInput,
]);

Exploit: (Educational Purposes!)

<!-- Example payload injected into a debug page parameter -->
<img src=x onerror=alert(document.domain)>
GET /debug-endpoint?param=<img src=x onerror=alert(1)> HTTP/1.1
Host: vulnerable-laravel-app.com

Protection: from this CVE

  • Set `APP_DEBUG=false` in `.env` for all staging and production environments.
  • Upgrade `laravel/framework` to version `12.69.0` or `13.30.0` (or later).
  • Restrict access to debug pages using IP allowlisting or intranet-only policies.
  • Implement Content Security Policy (CSP) headers that block inline script execution.
  • Audit custom Tippy.js configurations to ensure `allowHTML` is not enabled with untrusted input.

Impact:

DOM-based XSS allows execution of arbitrary JavaScript in the victim’s browser session, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of the user. The low severity reflects the requirement for `APP_DEBUG=true` and user interaction (hover), but the impact escalates in environments where debug mode is inadvertently exposed.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top