Junglewise Threat Intelligence

CVE-2026-45072: Symfony stored XSS in WebProfiler CodeExtension fileExcerpt

CVE-2026-45072 · Severity: medium · CVSS 4 · Published 2026-07-14

Technologies: Symfony. Vendors: Symfony.

Executive brief

Symfony, a popular web development framework, contains a security flaw in its development profiler tool. The tool fails to properly clean up non-PHP files, such as log files, before displaying them to developers. If an attacker can write malicious code into a file that a developer later views through this profiler, they could execute unauthorized scripts in the developer's browser, potentially leading to session theft or further compromise of the development environment.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Symfony TwigBridge and WebProfilerBundle. The 'file_excerpt' Twig filter, used within the development profiler, correctly escapes PHP files using highlight_string() but fails to sanitize content from non-PHP files (such as .log or .html files) before interpolating them into <code> elements. An attacker who can influence the content of files read by the profiler—such as writing to 'var/log/dev.log'—can execute arbitrary JavaScript in the context of a developer's browser session when they view the affected file. The issue is fixed in Symfony versions 6.4.40, 7.4.12, and 8.0.12.

Affected products

  • symfony symfony >= 6.4.24, < 6.4.40; >= 7.2.9, < 7.4.12; >= 8.0.0-BETA1, < 8.0.12
  • symfony twig-bridge >= 6.4.24, < 6.4.40
  • symfony web-profiler-bundle >= 7.2.9, < 7.4.12; >= 8.0.0-BETA1, < 8.0.12

Timeline

  • 2026-05-20: patched: Fixed in versions 6.4.40, 7.4.12, and 8.0.12
  • 2026-07-14: advisory: NVD publication date

References