CVE-2026-49216
MEDIUMSymfony UX: XSS in symfony/ux-autocomplete via unescaped AJAX response data
Title source: cnaDescription
Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX response items in _createAutocompleteWithRemoteData() by interpolating the text field into HTML template literals (<div>${item[labelField]}</div>) rather than text, allowing attacker-controlled markup from user-supplied dropdown values to execute in the browser of any user who opens an autocomplete widget backed by the same data. This issue is fixed in versions 2.36.0 and 3.1.0.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/symfony/ux/security/advisories/GHSA-mwqm-4fw3-cjvr
X_Refsource_Misc x_refsource_misc
https://github.com/symfony/ux/commit/842ae54bc74de389299f975f01aafae272cb0019
X_Refsource_Misc x_refsource_misc
https://github.com/symfony/ux/releases/tag/v2.36.0
X_Refsource_Misc x_refsource_misc
https://github.com/symfony/ux/releases/tag/v3.1.0
Scores
CVSS v3
5.4
EPSS
0.0018
EPSS Percentile
7.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (4)
symfony/ux
3.0.0
symfony/ux
2.2.0 - 2.36.0
symfony/ux
< 2.36.0
symfony/ux
>= 3.0.0, < 3.1.0
Published
Jul 17, 2026
Tracked Since
Jul 17, 2026