Vulnerability Details CVE-2026-55877
Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and Icon::toHtml() inlines SVG source verbatim, allowing unsanitized local SVG files or Iconify on-demand JSON body responses containing nested script elements, on* event handlers, or dangerous URL schemes to execute cross-site scripting. This issue is fixed in versions 2.36.1 and 3.2.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 27.3%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2026-55877
-
cpe:2.3:a:symfony:ux:2.17.0
-
cpe:2.3:a:symfony:ux:2.18.0
-
cpe:2.3:a:symfony:ux:2.18.1
-
cpe:2.3:a:symfony:ux:2.19.0
-
cpe:2.3:a:symfony:ux:2.19.1
-
cpe:2.3:a:symfony:ux:2.19.2
-
cpe:2.3:a:symfony:ux:2.19.3
-
cpe:2.3:a:symfony:ux:2.20.0
-
cpe:2.3:a:symfony:ux:2.21.0
-
cpe:2.3:a:symfony:ux:2.22.0
-
cpe:2.3:a:symfony:ux:2.22.1
-
cpe:2.3:a:symfony:ux:2.23.0
-
cpe:2.3:a:symfony:ux:2.24.0
-
cpe:2.3:a:symfony:ux:2.25.0
-
cpe:2.3:a:symfony:ux:2.25.1
-
cpe:2.3:a:symfony:ux:2.25.2
-
cpe:2.3:a:symfony:ux:2.26.0
-
cpe:2.3:a:symfony:ux:2.26.1
-
cpe:2.3:a:symfony:ux:2.27.0
-
cpe:2.3:a:symfony:ux:2.28.0
-
cpe:2.3:a:symfony:ux:2.28.1
-
cpe:2.3:a:symfony:ux:2.28.2
-
cpe:2.3:a:symfony:ux:2.29.0
-
cpe:2.3:a:symfony:ux:2.29.1
-
cpe:2.3:a:symfony:ux:2.29.2
-
cpe:2.3:a:symfony:ux:2.30.0
-
cpe:2.3:a:symfony:ux:2.31.0
-
cpe:2.3:a:symfony:ux:2.32.0
-
cpe:2.3:a:symfony:ux:2.33.0
-
cpe:2.3:a:symfony:ux:2.34.0
-
cpe:2.3:a:symfony:ux:2.35.0
-
cpe:2.3:a:symfony:ux:2.36.0
-
cpe:2.3:a:symfony:ux:3.0.0
-
cpe:2.3:a:symfony:ux:3.1.0