GHSA-jh5r-qr3c-85q8: XSS
Impact When APPDEBUG=true, attacker-controlled input is passed to a Tippy.js tooltip configured with allowHTML: true, enabling DOM-based XSS during mouse hover.
Patches #61381
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/laravel/frameworkto a version that resolves this vulnerability.Fixed in 13.30.0 - Upgrade
Upgrade
composer/laravel/frameworkto a version that resolves this vulnerability.Fixed in 12.69.0 - Upgrade
Upgrade
laravel/frameworkto a version that resolves this vulnerability.Patch #61381
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
The issue affects deployments where APP_DEBUG is set to true and attacker-controlled input reaches the affected Tippy.js tooltip. It is triggered when a user hovers over that tooltip.
What does an attacker need to exploit it?
An attacker needs a way to supply input that is rendered in the affected tooltip. Exploitation also requires a user interaction: the target must hover over the tooltip.
Is a default production configuration affected?
The provided information identifies APP_DEBUG=true as a required condition. It does not establish that this setting is enabled by default in any particular deployment.
What can be done before applying the patch?
Disable debug mode by setting APP_DEBUG to false. Also prevent untrusted input from reaching the affected tooltip path where possible.