Junglewise Threat Intelligence

CVE-2026-45753: Symfony HtmlSanitizer XSS via incomplete URL attribute list

CVE-2026-45753 · Severity: medium · CVSS 4 · Published 2026-07-14

Technologies: Symfony HtmlSanitizer. Vendors: Symfony.

Executive brief

A vulnerability exists in the Symfony PHP framework's HTML sanitization component, which is used to clean user-provided content to prevent malicious code execution. Due to an incomplete list of protected attributes, certain URL-based fields like form actions or video posters may not be properly cleaned. This could allow an attacker to inject malicious scripts that execute in a victim's browser when they interact with the affected page, potentially leading to unauthorized actions or data theft.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Symfony HtmlSanitizer component. The 'UrlAttributeSanitizer::getSupportedAttributes()' method fails to include several URL-valued attributes, specifically 'action', 'formaction', 'poster', and 'cite'. If a developer configures the sanitizer to allow these attributes, malicious 'javascript:' URIs will not be neutralized. An attacker can exploit this by providing a crafted URI that executes arbitrary JavaScript when a victim renders the HTML, submits a form, or clicks a button. The issue is resolved in versions 6.4.40, 7.4.12, and 8.0.12.

Affected products

  • Symfony symfony/symfony >= 6.1.0-BETA1, < 6.4.40
  • Symfony symfony/symfony >= 7.0.0-BETA1, < 7.4.12
  • Symfony symfony/symfony >= 8.0.0-BETA1, < 8.0.12
  • Symfony symfony/html-sanitizer >= 6.1.0-BETA1, < 6.4.40
  • Symfony symfony/html-sanitizer >= 7.0.0-BETA1, < 7.4.12
  • Symfony symfony/html-sanitizer >= 8.0.0-BETA1, < 8.0.12

Timeline

  • 2026-05-20: patched: Versions 6.4.40, 7.4.12, and 8.0.12 released
  • 2026-07-14: advisory: Public advisory and CVE published

References

Related threats