CVE-2026-102279: Laravel Framework
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixed in versions 12.69.0 and 13.30.0.
Affected products
- Laravel Framework: before 12.69.0 (fixed in 12.69.0); from 13.0.0, before 13.30.0 (fixed in 13.30.0)
Published 2026-09-28. Last modified 2026-09-30.