GHSA-5j3w-5pcr-f8hg

Suggest an improvement
Source
https://github.com/advisories/GHSA-5j3w-5pcr-f8hg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-5j3w-5pcr-f8hg/GHSA-5j3w-5pcr-f8hg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5j3w-5pcr-f8hg
Aliases
Published
2025-05-19T22:24:45Z
Modified
2025-08-29T21:46:48Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
Details

Impact

Rendering {{ attributes }} or using any method that returns a ComponentAttributes instance (e.g. only(), defaults(), without()) ouputs attribute values directly without escaping. If these values are unsafe (e.g. contain user input), this can lead to HTML attribute injection and XSS vulnerabilities.

Patches

The issue is fixed in version 2.25.1 of symfony/ux-twig-component by using Twig's EscaperRuntime to properly escape HTML attributes in ComponentAttributes. If you use symfony/ux-live-component, you must also update it to 2.25.1 to benefit from the fix, as it reuses the ComponentAttributes class internally.

Workarounds

Until you can upgrade, avoid rendering {{ attributes }} or derived objects directly if it may contain untrusted values. Instead, use {{ attributes.render('name') }} for safe output of individual attributes.

References

GitHub repository: symfony/ux

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-05-19T22:24:45Z",
    "nvd_published_at":  "2025-05-19T20:15:26Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / symfony/ux-twig-component

Package

Name
symfony/ux-twig-component
Purl
pkg:composer/symfony/ux-twig-component

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.25.1

Affected versions

v2.*
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v2.9.2
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.3
v2.14.0
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-5j3w-5pcr-f8hg/GHSA-5j3w-5pcr-f8hg.json"

Packagist / symfony/ux-live-component

Package

Name
symfony/ux-live-component
Purl
pkg:composer/symfony/ux-live-component

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.25.1

Affected versions

v2.*
v2.0.0
v2.0.1
v2.1.0
v2.1.1
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.2
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-5j3w-5pcr-f8hg/GHSA-5j3w-5pcr-f8hg.json"