Sep 29, 2026·5 min read·5 visits
A DOM-based Cross-Site Scripting (XSS) flaw inside the Laravel framework exception renderer allows remote code execution in administrative sessions. The flaw triggers when debugging mode is active and a user hovers over interactive tooltips managed by Tippy.js with allowHTML enabled.
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Laravel exception debug page rendering pipeline when APP_DEBUG=true is active. This flaw allows an attacker to execute arbitrary client-side JavaScript in the security context of an authenticated user's session when they hover over interactive code-trace tooltips handled by Tippy.js.
The Laravel framework exception handler contains an interactive debug interface triggered when the application runtime encounters an unhandled exception. This error-reporting pipeline is active when the configuration variable APP_DEBUG is set to true inside the environment file. It presents detailed diagnostics, including environmental parameters, exception metadata, and active stack traces with local code context.
The vulnerability is classified as a DOM-based Cross-Site Scripting (XSS) vulnerability mapping to CWE-80. It manifests inside the exception debug interface where client-side interactions occur. The component parses code snippets into tooltips to enhance usability during debugging sessions.
An external actor can exploit this mechanism by injecting client-side script payloads into fields that are subsequently rendered within an error trace. When a developer or administrator hovers over the affected tooltip element in their browser, the raw payload executes in the context of the active administrative origin.
The security boundary failure stems from a mismatch between server-side HTML entity encoding and the client-side retrieval of attribute values. The Laravel Blade template engine safely displays variables using double curly braces, which convert potentially harmful HTML characters into safe entities. This server-side encoding ensures that the markup structure remains intact when the browser initially loads the document.
However, the frontend utilizes Tippy.js to handle interactive tooltips dynamically. To determine what text to render inside the tooltip, Tippy.js retrieves values using the standard DOM method element.getAttribute('data-tippy-content'). Under the HTML Living Standard, calling getAttribute on an HTML node returns the value after the browser has automatically decoded the entities back into raw characters.
Because the global configuration of Tippy.js on this page explicitly set the allowHTML property to true, the library inserted the retrieved, unescaped string directly into the tooltip popup DOM tree using unsafe assignments. This sequence bypasses the original template security controls and allows a parsed HTML script block to run within the document structure.
The remediation modified the Blade template file located at src/Illuminate/Foundation/resources/exceptions/renderer/components/formatted-source.blade.php. In the vulnerable state, the template used the standard data-tippy-content attribute to pass the source code string.
<!-- Vulnerable Code -->
<x-code-renderer
language="php"
truncate
class="text-xs min-w-0"
data-tippy-content="{{ $source }}"
/>The fix changes this attribute to data-tippy-html-content to distinguish content that needs HTML interpretation from content that requires simple text insertion. The default data-tippy-content target is then modified on the client-side.
<!-- Patched Code -->
<x-code-renderer
language="php"
truncate
class="text-xs min-w-0"
data-tippy-html-content="{{ $source }}"
/>Inside scripts.js, the initialization was decoupled. The global selector [data-tippy-content] is now explicitly configured with allowHTML: false, preventing any HTML parsing for standard tooltips. Only nodes marked explicitly with [data-tippy-html-content] will invoke HTML rendering, limiting the impact to trusted or isolated context fields.
To execute this attack, specific preconditions must be satisfied. First, the targeted Laravel installation must run in debug mode (APP_DEBUG=true). Second, the attacker must find a mechanism to inject input containing malicious scripts into an element that the application includes inside an exception trace.
This input can be passed via application parameters, HTTP request headers, or database records that trigger downstream exceptions during execution. For instance, sending structural JSON payloads that cause parsing failures can force the exception renderer to output the malformed code within the source trace container.
Once the page renders, the browser converts safe entities back into executable formats inside the DOM node. The actual exploit execution remains dormant until an authorized administrator or developer triggers the event. The payload executes when the user hovers their pointer over the interactive tooltip node containing the formatted source.
The successful exploitation of this DOM-based XSS vulnerability allows an attacker to execute arbitrary client-side JavaScript. This execution occurs within the session context of the developer or administrative user who is viewing the debug screen.
Depending on the application architecture, this access can lead to session hijacking, administrative credential theft via session storage access, or the execution of unauthorized transactions on behalf of the user. Because debug mode is frequently enabled on staging environments that share secrets with production systems, this compromise can lead to broader infrastructure access.
CVSS assigns a score of 3.1, classifying the severity as Low. This rating reflects the high attack complexity and mandatory user interaction required to trigger execution, which reduces the likelihood of automated, scalable exploitation.
The primary remediation strategy is upgrading the Laravel framework. Organizations should deploy version 12.69.0 or 13.30.0 or higher depending on their major version branch. These releases include the updated Tippy.js selector division that disables HTML parsing by default.
In environments where upgrading is not immediately feasible, organizations must ensure that APP_DEBUG is set to false in all publicly accessible configurations. This disables the detailed exception rendering pipeline entirely, eliminating the attack surface.
Deploying a robust Content Security Policy (CSP) can further contain the risk. Enforcing a policy that restricts inline scripts (script-src 'self') and bans the use of unsafe-eval prevents the execution of arbitrary payloads injected through dynamic library manipulation.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
laravel/framework Laravel | < 12.69.0 | 12.69.0 |
laravel/framework Laravel | >= 13.0.0, < 13.30.0 | 13.30.0 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-80 |
| Attack Vector | Network |
| CVSS Severity Score | 3.1 (Low) |
| EPSS Score | 0.00202 (Percentile: 9.02%) |
| Exploit Status | Proof of Concept |
| CISA KEV Status | Not Listed |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
An uncontrolled recursion vulnerability exists in Nodemailer versions up to and including 10.0.1. When parsing recipient email addresses, recursively nested arrays bypass the parser's depth limit, resulting in V8 call stack exhaustion and immediate synchronous process termination.
A critical denial-of-service vulnerability in the adm-zip npm package allows attackers to bypass decompression-bomb protections introduced in version 0.5.18. By declaring the uncompressed file size as exactly 0, an attacker can disable the maxOutputLength constraint in the Node.js zlib wrapper, leading to complete system memory exhaustion and process crashes.
An uncontrolled resource consumption vulnerability in the logs SDK of OpenTelemetry-Go allows remote attackers to trigger a denial of service. Under conditions of downstream exporter backpressure, the BatchingProcessor enters a tight loop, exhausting CPU resources. This occurs because the processor immediately schedules retry attempts without waiting for its ticker interval, spinning continuously when the internal queue remains filled above the batch size. The issue affects all versions prior to v0.21.0 of the go.opentelemetry.io/otel/sdk/log package.
CVE-2026-76844 is a high-severity path traversal vulnerability in webpack-dev-middleware affecting multiple version branches. It stems from an incomplete fix for CVE-2024-29180 when serving files via a physical filesystem with a non-slash-terminated publicPath configuration. Attackers can bypass directory validation to access files situated one level above the intended output directory.
A Server-Side Request Forgery (SSRF) vulnerability exists in FasterXML jackson-databind before versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1. The flaw occurs during the deserialization of java.net.InetAddress fields, where the library implicitly triggers eager DNS lookups. Unauthenticated remote attackers can exploit this behavior by passing arbitrary hostnames in JSON fields, forcing target servers to make outbound DNS lookup requests.
An insecure deserialization vulnerability exists in FasterXML jackson-databind due to improper validation of URI schemes when resolving java.nio.file.Path properties. When binding untrusted JSON input to a Path field, the deserializer resolves attacker-supplied URIs without restriction. If the scheme is unrecognized by the default filesystem, the application falls back to querying registered SPI FileSystemProvider instances, causing class loading and potential side effects in environments with custom providers.