Impact
The vulnerability involves an uncontrolled use of user‑supplied data in debug exception pages, resulting in DOM‑based XSS when the tooltip is hovered over. This flaw allows an attacker to inject malicious scripts that execute in the browser of any user viewing the error page, potentially exposing session cookies or performing unauthorized actions. Because the flaw relies on a debugging flag, the attack requires the application to have APP_DEBUG enabled, meaning the impact is primarily confined to development or incorrectly configured production environments.
Affected Systems
The flaw affects the Laravel framework, impacting all releases older than 12.69.0 and 13.30.0. Specifically, any application using Laravel 12.x prior to 12.69.0 or 13.x prior to 13.30.0 is vulnerable when APP_DEBUG is true. Updating to the indicated versions removes the vulnerability.
Risk and Exploitability
The CVSS score is 3.1, indicating a low severity. The EPSS score is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers must leverage the debug mode and be able to supply input that triggers the exception page. While the bug is relatively low risk in properly hardened production environments, it can be exploited by anyone who can reach the application with APP_DEBUG enabled, and it is therefore advisable to disable debugging on public deployments.
OpenCVE Enrichment