GHSA-p9xj-fpr2-jf2q

Suggest an improvement
Source
https://github.com/advisories/GHSA-p9xj-fpr2-jf2q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-p9xj-fpr2-jf2q/GHSA-p9xj-fpr2-jf2q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p9xj-fpr2-jf2q
Aliases
Published
2026-06-19T21:42:18Z
Modified
2026-09-10T03:51:09Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest
Details

Description

The ux:install console command installs files from a recipe kit by copying paths listed in a copy-files map. The only guard against malicious paths was Path::isRelative(), which returns true for paths like ../../../etc. Path::join() then resolves the .. segments without complaint, so the final path can escape the intended directory entirely. A crafted or compromised kit can therefore write attacker-controlled content to arbitrary locations on the developer's machine or CI runner.

Because the copy operation creates missing parent directories and can overwrite existing files silently (with --force or in non-interactive environments), an attacker who controls a kit can overwrite files such as controllers, git hooks, or .env to achieve code execution. The source side of copy-files is symmetrically affected, enabling local file reads outside the recipe directory.

Resolution

The fix introduces an Assert::pathDoesNotEscapeDirectory() helper that rejects any copy-files source or destination path containing a .. segment, regardless of whether / or \ is used as the separator. This check is enforced in both RecipeManifest (which also guards the source Finder) and File. As a last line of defense, the installer re-verifies the fully resolved paths with Path::isBasePath() immediately before each filesystem read and write.

Credits

Symfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-19T21:42:18Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Packagist / symfony/ux-toolkit

Package

Name
symfony/ux-toolkit
Purl
pkg:composer/symfony/ux-toolkit

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.32.0
Fixed
2.36.1

Affected versions

v2.*
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-p9xj-fpr2-jf2q/GHSA-p9xj-fpr2-jf2q.json"

Packagist / symfony/ux-toolkit

Package

Name
symfony/ux-toolkit
Purl
pkg:composer/symfony/ux-toolkit

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.2.0

Affected versions

v3.*
v3.0.0
v3.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-p9xj-fpr2-jf2q/GHSA-p9xj-fpr2-jf2q.json"