GHSA-5j3w-5pcr-f8hg
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
Quick fix
GHSA-5j3w-5pcr-f8hg — symfony/ux-twig-component: upgrade to the fixed version with the command below.
composer require symfony/ux-twig-component:^2.25.1Details
### Impact
Rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. `only()`, `defaults()`, `without()`) ouputs attribute values directly without escaping. If these values are unsafe (e.g. contain user input), this can lead to HTML attribute injection and XSS vulnerabilities.
### Patches
The issue is fixed in version `2.25.1` of `symfony/ux-twig-component` by using Twig's `EscaperRuntime` to properly escape HTML attributes in `ComponentAttributes`. If you use `symfony/ux-live-component`, you must also update it to `2.25.1` to benefit from the fix, as it reuses the `ComponentAttributes` class internally.
### Workarounds
Until you can upgrade, avoid rendering `{{ attributes }}` or derived objects directly if it may contain untrusted values. Instead, use `{{ attributes.render('name') }}` for safe output of individual attributes.
### References
GitHub repository: [symfony/ux](https://github.com/symfony/ux)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.25.1composer require symfony/ux-twig-component:^2.25.10Fixed in: 2.25.1composer require symfony/ux-live-component:^2.25.1References
- https://github.com/symfony/ux/security/advisories/GHSA-5j3w-5pcr-f8hg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-47946[ADVISORY]
- https://github.com/symfony/ux-live-component/commit/7ad44cf56d750b9f56658ed986286a10da132ee7[WEB]
- https://github.com/symfony/ux-twig-component/commit/b5d4e77db69315aeb18d2238e0e7c943d340ce76[WEB]
- https://github.com/symfony/ux/commit/b5d1c85995c128cb926d47a96cfbfbd500b643a8[WEB]
- https://github.com/symfony/ux/commit/c2f7738ee0969c31df7514025a7f5fc6e153932d[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/ux-live-component/CVE-2025-47946.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/ux-twig-component/CVE-2025-47946.yaml[WEB]
- https://github.com/symfony/ux[PACKAGE]
- https://symfony.com/blog/symfony-ux-cve-2025-47946-unsanitized-html-attribute-injection-via-componentattributes[WEB]