Executive brief
Symfony, a popular web development framework, contains a security flaw in its development profiler tool. The tool fails to properly clean up non-PHP files, such as log files, before displaying them to developers. If an attacker can write malicious code into a file that a developer later views through this profiler, they could execute unauthorized scripts in the developer's browser, potentially leading to session theft or further compromise of the development environment.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Symfony TwigBridge and WebProfilerBundle. The 'file_excerpt' Twig filter, used within the development profiler, correctly escapes PHP files using highlight_string() but fails to sanitize content from non-PHP files (such as .log or .html files) before interpolating them into <code> elements. An attacker who can influence the content of files read by the profiler—such as writing to 'var/log/dev.log'—can execute arbitrary JavaScript in the context of a developer's browser session when they view the affected file. The issue is fixed in Symfony versions 6.4.40, 7.4.12, and 8.0.12.
Affected products
- symfony symfony >= 6.4.24, < 6.4.40; >= 7.2.9, < 7.4.12; >= 8.0.0-BETA1, < 8.0.12
- symfony twig-bridge >= 6.4.24, < 6.4.40
- symfony web-profiler-bundle >= 7.2.9, < 7.4.12; >= 8.0.0-BETA1, < 8.0.12
Timeline
- 2026-05-20: patched: Fixed in versions 6.4.40, 7.4.12, and 8.0.12
- 2026-07-14: advisory: NVD publication date
References
- https://github.com/symfony/symfony/commit/863aa81c61166f1aa74b7732df316f76113acbdb
- https://github.com/symfony/symfony/releases/tag/v6.4.40
- https://github.com/symfony/symfony/releases/tag/v7.4.12
- https://github.com/symfony/symfony/releases/tag/v8.0.12
- https://github.com/symfony/symfony/security/advisories/GHSA-hmr5-2xcr-v8pp