CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-102279

CVE-2026-102279: DOM-based Cross-Site Scripting in Laravel Exception Debug Page via Tippy.js

Amit Schendel
Amit Schendel
Senior Security Researcher

Sep 29, 2026·5 min read·5 visits

Executive Summary (TL;DR)

A DOM-based Cross-Site Scripting (XSS) flaw inside the Laravel framework exception renderer allows remote code execution in administrative sessions. The flaw triggers when debugging mode is active and a user hovers over interactive tooltips managed by Tippy.js with allowHTML enabled.

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Laravel exception debug page rendering pipeline when APP_DEBUG=true is active. This flaw allows an attacker to execute arbitrary client-side JavaScript in the security context of an authenticated user's session when they hover over interactive code-trace tooltips handled by Tippy.js.

Vulnerability Overview

The Laravel framework exception handler contains an interactive debug interface triggered when the application runtime encounters an unhandled exception. This error-reporting pipeline is active when the configuration variable APP_DEBUG is set to true inside the environment file. It presents detailed diagnostics, including environmental parameters, exception metadata, and active stack traces with local code context.

The vulnerability is classified as a DOM-based Cross-Site Scripting (XSS) vulnerability mapping to CWE-80. It manifests inside the exception debug interface where client-side interactions occur. The component parses code snippets into tooltips to enhance usability during debugging sessions.

An external actor can exploit this mechanism by injecting client-side script payloads into fields that are subsequently rendered within an error trace. When a developer or administrator hovers over the affected tooltip element in their browser, the raw payload executes in the context of the active administrative origin.

Root Cause Analysis

The security boundary failure stems from a mismatch between server-side HTML entity encoding and the client-side retrieval of attribute values. The Laravel Blade template engine safely displays variables using double curly braces, which convert potentially harmful HTML characters into safe entities. This server-side encoding ensures that the markup structure remains intact when the browser initially loads the document.

However, the frontend utilizes Tippy.js to handle interactive tooltips dynamically. To determine what text to render inside the tooltip, Tippy.js retrieves values using the standard DOM method element.getAttribute('data-tippy-content'). Under the HTML Living Standard, calling getAttribute on an HTML node returns the value after the browser has automatically decoded the entities back into raw characters.

Because the global configuration of Tippy.js on this page explicitly set the allowHTML property to true, the library inserted the retrieved, unescaped string directly into the tooltip popup DOM tree using unsafe assignments. This sequence bypasses the original template security controls and allows a parsed HTML script block to run within the document structure.

Code Analysis

The remediation modified the Blade template file located at src/Illuminate/Foundation/resources/exceptions/renderer/components/formatted-source.blade.php. In the vulnerable state, the template used the standard data-tippy-content attribute to pass the source code string.

<!-- Vulnerable Code -->
<x-code-renderer 
    language="php"
    truncate
    class="text-xs min-w-0"
    data-tippy-content="{{ $source }}"
/>

The fix changes this attribute to data-tippy-html-content to distinguish content that needs HTML interpretation from content that requires simple text insertion. The default data-tippy-content target is then modified on the client-side.

<!-- Patched Code -->
<x-code-renderer 
    language="php"
    truncate
    class="text-xs min-w-0"
    data-tippy-html-content="{{ $source }}"
/>

Inside scripts.js, the initialization was decoupled. The global selector [data-tippy-content] is now explicitly configured with allowHTML: false, preventing any HTML parsing for standard tooltips. Only nodes marked explicitly with [data-tippy-html-content] will invoke HTML rendering, limiting the impact to trusted or isolated context fields.

Exploitation Methodology

To execute this attack, specific preconditions must be satisfied. First, the targeted Laravel installation must run in debug mode (APP_DEBUG=true). Second, the attacker must find a mechanism to inject input containing malicious scripts into an element that the application includes inside an exception trace.

This input can be passed via application parameters, HTTP request headers, or database records that trigger downstream exceptions during execution. For instance, sending structural JSON payloads that cause parsing failures can force the exception renderer to output the malformed code within the source trace container.

Once the page renders, the browser converts safe entities back into executable formats inside the DOM node. The actual exploit execution remains dormant until an authorized administrator or developer triggers the event. The payload executes when the user hovers their pointer over the interactive tooltip node containing the formatted source.

Impact Assessment

The successful exploitation of this DOM-based XSS vulnerability allows an attacker to execute arbitrary client-side JavaScript. This execution occurs within the session context of the developer or administrative user who is viewing the debug screen.

Depending on the application architecture, this access can lead to session hijacking, administrative credential theft via session storage access, or the execution of unauthorized transactions on behalf of the user. Because debug mode is frequently enabled on staging environments that share secrets with production systems, this compromise can lead to broader infrastructure access.

CVSS assigns a score of 3.1, classifying the severity as Low. This rating reflects the high attack complexity and mandatory user interaction required to trigger execution, which reduces the likelihood of automated, scalable exploitation.

Remediation & Mitigation

The primary remediation strategy is upgrading the Laravel framework. Organizations should deploy version 12.69.0 or 13.30.0 or higher depending on their major version branch. These releases include the updated Tippy.js selector division that disables HTML parsing by default.

In environments where upgrading is not immediately feasible, organizations must ensure that APP_DEBUG is set to false in all publicly accessible configurations. This disables the detailed exception rendering pipeline entirely, eliminating the attack surface.

Deploying a robust Content Security Policy (CSP) can further contain the risk. Enforcing a policy that restricts inline scripts (script-src 'self') and bans the use of unsafe-eval prevents the execution of arbitrary payloads injected through dynamic library manipulation.

Official Patches

LaravelFix commit implementing safe CSS selectors for context parsing
LaravelPull request merging the fix into the exception template pipeline

Fix Analysis (1)

Technical Appendix

CVSS Score
3.1/ 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Probability
0.20%
Top 91% most exploited

Affected Systems

Laravel applications running versions < 12.69.0 with active debug configurationsLaravel applications running versions >= 13.0.0 and < 13.30.0 with active debug configurations

Affected Versions Detail

Product
Affected Versions
Fixed Version
laravel/framework
Laravel
< 12.69.012.69.0
laravel/framework
Laravel
>= 13.0.0, < 13.30.013.30.0
AttributeDetail
CWE IDCWE-80
Attack VectorNetwork
CVSS Severity Score3.1 (Low)
EPSS Score0.00202 (Percentile: 9.02%)
Exploit StatusProof of Concept
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1204.002User Execution: Malicious Link / Interaction
Execution
T1189Drive-by Compromise
Initial Access
T1059.007Command and Scripting Interpreter: JavaScript
Execution
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Vulnerability Timeline

Vulnerability patch developed and merged inside Laravel Framework source layout files.
2026-08-31
GitHub Security Advisory GHSA-jh5r-qr3c-85q8 published alongside fixed framework releases.
2026-09-28
CVE-2026-102279 published by CVE program authorizers.
2026-09-28

References & Sources

  • [1]GitHub Security Advisory GHSA-jh5r-qr3c-85q8
  • [2]NVD CVE-2026-102279 Analysis
  • [3]CVE-2026-102279 Record

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•3 minutes ago•GHSA-8VVX-RFF5-P5RQ
5.9

GHSA-8vvx-rff5-p5rq: Stack Exhaustion Denial of Service via Nested Recipient Arrays in Nodemailer

An uncontrolled recursion vulnerability exists in Nodemailer versions up to and including 10.0.1. When parsing recipient email addresses, recursively nested arrays bypass the parser's depth limit, resulting in V8 call stack exhaustion and immediate synchronous process termination.

Alon Barad
Alon Barad
0 views•7 min read
•about 2 hours ago•GHSA-RCW4-F5RP-G42V
7.5

GHSA-RCW4-F5RP-G42V: Uncontrolled Resource Consumption and Decompression Bomb Protection Bypass in adm-zip

A critical denial-of-service vulnerability in the adm-zip npm package allows attackers to bypass decompression-bomb protections introduced in version 0.5.18. By declaring the uncompressed file size as exactly 0, an attacker can disable the maxOutputLength constraint in the Node.js zlib wrapper, leading to complete system memory exhaustion and process crashes.

Alon Barad
Alon Barad
6 views•8 min read
•about 3 hours ago•CVE-2026-81872
6.3

CVE-2026-81872: CPU Exhaustion via Tight Loop in OpenTelemetry-Go BatchingProcessor

An uncontrolled resource consumption vulnerability in the logs SDK of OpenTelemetry-Go allows remote attackers to trigger a denial of service. Under conditions of downstream exporter backpressure, the BatchingProcessor enters a tight loop, exhausting CPU resources. This occurs because the processor immediately schedules retry attempts without waiting for its ticker interval, spinning continuously when the internal queue remains filled above the batch size. The issue affects all versions prior to v0.21.0 of the go.opentelemetry.io/otel/sdk/log package.

Alon Barad
Alon Barad
9 views•7 min read
•about 4 hours ago•CVE-2026-76844
7.4

CVE-2026-76844: Path Traversal in webpack-dev-middleware via Incomplete Prefix Validation

CVE-2026-76844 is a high-severity path traversal vulnerability in webpack-dev-middleware affecting multiple version branches. It stems from an incomplete fix for CVE-2024-29180 when serving files via a physical filesystem with a non-slash-terminated publicPath configuration. Attackers can bypass directory validation to access files situated one level above the intended output directory.

Amit Schendel
Amit Schendel
9 views•5 min read
•about 11 hours ago•CVE-2026-77310
5.3

CVE-2026-77310: Server-Side Request Forgery via DNS Resolution in jackson-databind

A Server-Side Request Forgery (SSRF) vulnerability exists in FasterXML jackson-databind before versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1. The flaw occurs during the deserialization of java.net.InetAddress fields, where the library implicitly triggers eager DNS lookups. Unauthenticated remote attackers can exploit this behavior by passing arbitrary hostnames in JSON fields, forcing target servers to make outbound DNS lookup requests.

Alon Barad
Alon Barad
8 views•4 min read
•about 12 hours ago•CVE-2026-19032
5.3

CVE-2026-19032: Insecure Deserialization and Class Loading via java.nio.file.Path Resolution in FasterXML jackson-databind

An insecure deserialization vulnerability exists in FasterXML jackson-databind due to improper validation of URI schemes when resolving java.nio.file.Path properties. When binding untrusted JSON input to a Path field, the deserializer resolves attacker-supplied URIs without restriction. If the scheme is unrecognized by the default filesystem, the application falls back to querying registered SPI FileSystemProvider instances, causing class loading and potential side effects in environments with custom providers.

Alon Barad
Alon Barad
12 views•6 min read