news.mlab.sh
Back to the feed
vulnerability

Vulnérabilité dans Laravel (10 septembre 2026)

Medium
Summary

A vulnerability in Laravel versions prior to 13.30.0 and 12.69.0 allows for remote code injection via XSS. This means attackers could potentially execute malicious code on vulnerable systems without requiring local access.

A security vulnerability has been identified within the Laravel framework. This vulnerability enables attackers to trigger a remote code injection via Cross-Site Scripting (XSS). The issue stems from a flaw in how Laravel handles indirect code injection, allowing attackers to introduce malicious scripts into a website or application. The vulnerability is present in Laravel versions 13.x prior to 13.30.0 and 12.69.0. The CERT-FR has released a security advisory detailing the issue and recommending users update to a patched version.

Read the full article at CERT-FR