Executive brief
A vulnerability exists in the Symfony PHP framework's HTML sanitization component, which is used to clean user-provided content to prevent malicious code execution. Due to an incomplete list of protected attributes, certain URL-based fields like form actions or video posters may not be properly cleaned. This could allow an attacker to inject malicious scripts that execute in a victim's browser when they interact with the affected page, potentially leading to unauthorized actions or data theft.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Symfony HtmlSanitizer component. The 'UrlAttributeSanitizer::getSupportedAttributes()' method fails to include several URL-valued attributes, specifically 'action', 'formaction', 'poster', and 'cite'. If a developer configures the sanitizer to allow these attributes, malicious 'javascript:' URIs will not be neutralized. An attacker can exploit this by providing a crafted URI that executes arbitrary JavaScript when a victim renders the HTML, submits a form, or clicks a button. The issue is resolved in versions 6.4.40, 7.4.12, and 8.0.12.
Affected products
- Symfony symfony/symfony >= 6.1.0-BETA1, < 6.4.40
- Symfony symfony/symfony >= 7.0.0-BETA1, < 7.4.12
- Symfony symfony/symfony >= 8.0.0-BETA1, < 8.0.12
- Symfony symfony/html-sanitizer >= 6.1.0-BETA1, < 6.4.40
- Symfony symfony/html-sanitizer >= 7.0.0-BETA1, < 7.4.12
- Symfony symfony/html-sanitizer >= 8.0.0-BETA1, < 8.0.12
Timeline
- 2026-05-20: patched: Versions 6.4.40, 7.4.12, and 8.0.12 released
- 2026-07-14: advisory: Public advisory and CVE published
References
- https://github.com/symfony/symfony/commit/487728e7e180a674a6d4c01bd0cb56161cc441b7
- https://github.com/symfony/symfony/releases/tag/v6.4.40
- https://github.com/symfony/symfony/releases/tag/v7.4.12
- https://github.com/symfony/symfony/releases/tag/v8.0.12
- https://github.com/symfony/symfony/security/advisories/GHSA-hhg7-c65m-h7ff