Junglewise Threat Intelligence

CVE-2026-55878: Symfony UX Toolkit path traversal in ux:install command

CVE-2026-55878 · Severity: high · CVSS 7.8 · Published 2026-07-08

Vendors: Symfony.

Executive brief

Symfony UX is a set of tools used by developers to integrate JavaScript into Symfony web applications. A security flaw in its installation command allows a malicious or compromised "recipe kit" to write files to unauthorized locations on a developer's computer or automated build system. This could allow an attacker to overwrite critical system files, steal sensitive data, or gain full control over the affected machine when a developer attempts to install a malicious package.

Technical details

A path traversal vulnerability exists in the `ux:install` console command of Symfony UX Toolkit. The command processes a `copy-files` map from recipe kits using `Path::isRelative()`, which fails to block relative path segments like `../../`. An attacker can craft a malicious recipe manifest that uses these segments to escape the intended directory, enabling arbitrary file writes (e.g., overwriting controllers or git hooks) and arbitrary file reads on the host system. The vulnerability is exploited when a user interacts with a compromised kit. The fix introduces `Assert::pathDoesNotEscapeDirectory()` to reject paths containing `..` segments and adds `Path::isBasePath()` checks before filesystem operations.

Affected products

  • Symfony ux-toolkit >= 2.32.0, < 2.36.1; >= 3.0.0, < 3.2.0

Timeline

  • 2026-06-19: patched: Fixes released in versions 2.36.1 and 3.2.0
  • 2026-07-08: advisory: CVE-2026-55878 published

References