Intel

AIKIDO-2026-597742

albertoarena/laravel-truss is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)GHSA-g6ch-v573-cxxw Published Yesterday

35

Low Risk

This Affects:

PHPalbertoarena/laravel-truss
1.14.0 - 1.14.0
Fixed in 1.14.1
Are you affected? Scan for Free

TL;DR

The HTML export embeds the database schema as JSON inside a <script type="application/json"> element, using json_encode() without JSON_HEX_TAG. A table name, index name, or column default that contains a literal </script> ends the script element early, so the browser processes the rest of the exported document as markup and the export looks truncated to the person who ran it. An attacker must already be able to set a hostile table name, index name, or column default in the database before the export runs. The fix adds JSON_HEX_TAG to the encoder so < and > in embedded values are escaped and cannot break out of the script element.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use truss:export --format=html to export a schema that contains a table name, index name, or column default you do not fully control.

Background info

albertoarena/laravel-truss is vulnerable to Cross-Site Scripting (XSS) in versions 1.14.0 - 1.14.0.

How to fix this

Upgrade the albertoarena/laravel-truss library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform