VORANT. Threat Intelligence Sign in Get the full feed

Laravel Framework Patches XSS Vulnerability

routine vulnerability technology

ANSSI advisory warns of a cross-site scripting flaw in Laravel framework versions before 13.30.0 and 12.69.0, patches available.

The French national cybersecurity agency (CERT-FR/ANSSI) published an advisory covering a vulnerability in the Laravel PHP framework that allows an attacker to conduct indirect remote code injection, specifically cross-site scripting (XSS). The issue affects laravel/framework versions in the 13.x line prior to 13.30.0, as well as versions prior to 12.69.0 in the earlier branch.

No indication of active exploitation in the wild is mentioned in the advisory. Defenders running affected Laravel versions should upgrade to the patched releases (13.30.0 or 12.69.0 and later) per the vendor's GitHub security advisory (GHSA-jh5r-qr3c-85q8), published September 10, 2026. As with any XSS vulnerability, organizations should also review input sanitization and output encoding practices in applications built on affected Laravel versions as a defense-in-depth measure while patching is rolled out.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1153

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free