CVE-2025-26159

MEDIUM

laravel-starter < 11.11.0 - Stored Cross-Site Scripting in Tags Feature

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-26159. PoCs published by godBADTRY.

AI-analyzed exploit summary This PoC demonstrates an XSS vulnerability in Laravel Starter by extracting session cookies via a malicious script injected into the tag name field. The server component listens for and decodes stolen cookies sent via a fetch request.

Description

Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field.

Exploits (1)

nomisec WORKING POC
by godBADTRY · poc
https://github.com/godBADTRY/CVE-2025-26159

This PoC demonstrates an XSS vulnerability in Laravel Starter by extracting session cookies via a malicious script injected into the tag name field. The server component listens for and decodes stolen cookies sent via a fetch request.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Laravel Starter (version not specified)
No auth needed
Prerequisites: Victim must visit a page with the malicious tag · Attacker must control or inject the tag name field
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0024
EPSS Percentile 46.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
nasirkhan/laravel-starter 0 - 11.11.0Packagist
Published Apr 22, 2025
Tracked Since Feb 18, 2026