Junglewise Threat Intelligence

CVE-2026-48761: Symfony HtmlSanitizer XSS via incomplete URL attribute sanitization

CVE-2026-48761 · Severity: medium · CVSS 4 · Published 2026-07-14

Technologies: Symfony HtmlSanitizer, Symfony. Vendors: Symfony.

Executive brief

Symfony is a popular PHP framework used to build web applications. A vulnerability in its HTML sanitization component could allow malicious scripts to bypass security filters when certain HTML tags like iframes or images are used. This could lead to cross-site scripting (XSS) attacks, potentially allowing an attacker to hijack user sessions or steal sensitive information from people visiting the affected website.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Symfony HtmlSanitizer component due to incomplete attribute coverage in UrlAttributeSanitizer::getSupportedAttributes(). The sanitizer omitted URL-bearing attributes for <object>, <applet>, <iframe>, and <img> tags, and failed to sanitize URLs within <meta http-equiv="refresh"> content. An attacker can exploit this by providing specially crafted HTML containing 'javascript:' or similar malicious payloads that bypass the sanitizer. This allows for the execution of arbitrary JavaScript in the context of the victim's browser. The issue is fixed in Symfony versions 6.4.41, 7.4.13, and 8.0.13.

Affected products

  • Symfony Symfony >= 6.1.0, < 6.4.41; >= 7.0.0-BETA1, < 7.4.13; >= 8.0.0-BETA1, < 8.0.13
  • Symfony html-sanitizer >= 6.1.0, < 6.4.41; >= 7.0.0-BETA1, < 7.4.13; >= 8.0.0-BETA1, < 8.0.13

Timeline

  • 2026-07-14: advisory: NVD publication date
  • 2026-05-27: patched: Release of fixed versions 6.4.41, 7.4.13, and 8.0.13

References

Related threats