Junglewise Threat Intelligence

CVE-2026-49215: Symfony UX LiveComponent CSRF in LiveAction invocations

CVE-2026-49215 · Severity: medium · CVSS 4 · Published 2026-07-17

Technologies: Symfony UX Live Component. Vendors: Symfony.

Executive brief

A security flaw in the Symfony UX LiveComponent library could allow an attacker to perform unauthorized actions on behalf of a user. The library incorrectly relied on a specific web header for security that can actually be manipulated by malicious websites. If a user visits a malicious site while logged into an affected Symfony application, the attacker might be able to trigger server-side changes or data modifications, particularly in applications with non-standard cookie security settings.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in Symfony UX LiveComponent due to insufficient request validation in LiveComponentSubscriber::isLiveComponentRequest(). The component previously relied on the 'Accept: application/vnd.live-component+html' header to verify requests; however, because this header is CORS-safelisted, it can be set by cross-origin fetch() calls without triggering a CORS preflight. This allows an attacker to forge requests to #[LiveAction] methods. The vulnerability is most impactful in environments using 'SameSite=None' cookies or those susceptible to same-origin pivots. The fix introduces a requirement for the 'X-Requested-With' header, which is not CORS-safelisted and thus forces a preflight check that will fail for unauthorized cross-origin requests.

Affected products

  • Symfony ux-live-component >= 2.22.0, < 2.36.0; >= 3.0.0, < 3.1.0

Timeline

  • 2026-05-29: patched: Versions 2.36.0 and 3.1.0 released
  • 2026-05-29: advisory: GitHub Security Advisory GHSA-4m4j-hmqq-3gxm published
  • 2026-07-17: disclosed: CVE-2026-49215 published to NVD

References

Related threats