When APP_DEBUG=true, attacker-controlled input is passed to a Tippy.js tooltip configured with allowHTML: true, enabling DOM-based XSS during mouse hover.
{
"cwe_ids": [
"CWE-80"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T18:24:25Z",
"nvd_published_at": "2026-09-28T21:17:16Z",
"severity": "LOW"
}