{"id":"CVE-2026-102279","summary":"Laravel: XSS in Debug Page Information","details":"Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixed in versions 12.69.0 and 13.30.0.","aliases":["GHSA-jh5r-qr3c-85q8"],"modified":"2026-09-30T03:47:05.411877021Z","published":"2026-09-28T20:59:36.528Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102279.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-80"]},"references":[{"type":"WEB","url":"https://github.com/laravel/framework/releases/tag/v12.69.0"},{"type":"WEB","url":"https://github.com/laravel/framework/releases/tag/v13.30.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102279.json"},{"type":"ADVISORY","url":"https://github.com/laravel/framework/security/advisories/GHSA-jh5r-qr3c-85q8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102279"},{"type":"FIX","url":"https://github.com/laravel/framework/commit/b495ca2ec4e15a977e8700328bf13e8a79f29d12"},{"type":"FIX","url":"https://github.com/laravel/framework/pull/61381"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/laravel/framework","events":[{"introduced":"0"},{"introduced":"3e33f431a05365d008742ff8001b92641086d5f8"},{"fixed":"335429f28612e3a7810db0c8508b2cddbcc0fda0"},{"fixed":"9c008e7c9a64a8ea6d6e4f1683bd569acc10bf9e"},{"fixed":"b495ca2ec4e15a977e8700328bf13e8a79f29d12"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"12.69.0"},{"introduced":"13.0.0"},{"fixed":"13.30.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v13.29.0","v13.28.0","v12.68.0","v13.27.0","v13.26.1","v12.67.0","v13.26.0","v12.66.0","v13.25.0","v12.65.0","v13.24.0","v13.23.0","v13.22.0","v13.21.1","v13.21.0","v12.64.0","v13.20.0","v12.63.0","v13.19.0","v13.18.1","v13.18.0","v13.17.0","v13.16.1","v13.16.0","v12.62.0","v13.15.0","v13.14.0","v12.61.1","v13.13.0","v12.61.0","v13.12.0","v12.60.2","v13.11.2","v12.60.1","v13.11.1","v12.60.0","v13.11.0","v13.10.0","v12.59.0","v13.9.0","v13.8.0","v13.7.0","v12.58.0","v12.57.0","v13.6.0","v13.5.0","v13.4.0","v13.3.0","v12.56.0","v13.2.0","v13.1.1","v13.1.0","v12.55.1","v13.0.0","v12.55.0","v12.54.1","v12.54.0","v12.53.0","v12.52.0","v12.51.0","v12.50.0","v12.49.0","v12.48.1","v12.48.0","v12.47.0","v12.46.0","v12.45.2","v12.45.1","v12.45.0","v12.44.0","v12.43.1","v12.43.0","v12.42.0","v12.41.1","v12.41.0","v12.40.2","v12.40.0","v12.40.1","v12.39.0","v12.38.1","v12.38.0","v12.37.0","v12.36.1","v12.36.0","v12.35.1","v12.35.0","v12.34.0","v12.33.0","v12.32.5","v12.32.4","v12.32.3","v12.32.2","v12.32.1","v12.32.0","v12.31.1","v12.31.0","v12.30.1","v12.30.0","v12.29.0","v12.28.1","v12.28.0","v12.27.1","v12.26.4","v12.26.3","v12.26.2","v12.26.1","v12.26.0","v12.25.0","v12.24.0","v12.23.1","v12.23.0","v12.22.1","v12.22.0","v12.21.0","v12.20.0","v12.19.3","v12.19.2","v12.19.1","v12.19.0","v12.18.0","v12.17.0","v12.16.0","v12.15.0","v12.14.1","v12.14.0","v12.13.0","v12.12.0","v12.11.1","v12.11.0","v12.10.2","v12.10.1","v12.10.0","v12.9.2","v12.9.1","v12.9.0","v12.8.1","v12.8.0","v12.7.2","v12.7.1","v12.7.0","v12.6.0","v12.5.0","v12.4.1","v12.4.0","v12.3.0","v12.2.0","v12.1.1","v12.1.0","v12.0.1","v12.0.0","v9.0.0-beta.1","v8.17.2","v8.17.1","v8.17.0","v8.16.0","v8.15.0","v8.14.0","v8.13.0","v8.12.3","v8.12.2","v8.12.1","v8.12.0","v8.11.2","v8.11.0","v8.11.1","v8.9.0","v8.8.0","v8.7.1","v8.7.0","v8.6.0","v8.5.0","v8.4.0","v8.3.0","v8.2.0","v8.1.0","v8.0.4","v8.0.3","v8.0.2","v8.0.1","v8.0.0","v5.5.1","v5.5.0","v4.1.0","v4.0.0","v4.0.0-BETA4","v4.0.0-BETA3","v4.0.0-BETA2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102279.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}