The Laravel team has published framework release v12.69.0 on GitHub, tagged to the 12.x branch on September 1.
The release contains two changes, both contributed by crynobone. The exception page tooltip now disables HTML by default, closing a potential injection surface in the debug error rendering.
The second change hardens session authentication: before a user is authenticated via the remember-me cookie, Laravel now verifies that the password hash matches the value stored in that cookie. This prevents stale or tampered cookies from granting access after a password change.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.