VDB
Sign up
MEDIUM6.1

GHSA-5j3w-5pcr-f8hg

Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes

Quick fix

GHSA-5j3w-5pcr-f8hg — symfony/ux-twig-component: upgrade to the fixed version with the command below.

composer require symfony/ux-twig-component:^2.25.1

Details

### Impact

Rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. `only()`, `defaults()`, `without()`) ouputs attribute values directly without escaping. If these values are unsafe (e.g. contain user input), this can lead to HTML attribute injection and XSS vulnerabilities.

### Patches

The issue is fixed in version `2.25.1` of `symfony/ux-twig-component` by using Twig's `EscaperRuntime` to properly escape HTML attributes in `ComponentAttributes`. If you use `symfony/ux-live-component`, you must also update it to `2.25.1` to benefit from the fix, as it reuses the `ComponentAttributes` class internally.

### Workarounds

Until you can upgrade, avoid rendering `{{ attributes }}` or derived objects directly if it may contain untrusted values. Instead, use `{{ attributes.render('name') }}` for safe output of individual attributes.

### References

GitHub repository: [symfony/ux](https://github.com/symfony/ux)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/ux-twig-component
Introduced in: 0Fixed in: 2.25.1
Fixcomposer require symfony/ux-twig-component:^2.25.1
Packagist/symfony/ux-live-component
Introduced in: 0Fixed in: 2.25.1
Fixcomposer require symfony/ux-live-component:^2.25.1

References