{"id":"GHSA-53h4-8rc4-f539","summary":"Slim has Reflected XSS in the HtmlErrorRenderer","details":"### Impact\n\nIf an application uses `HttpException::setTitle()` and/or `setDescription()` to include untrusted/request-derived data in the error title or description (e.g. `\"No products found matching '{$query}'.\"`), an attacker could inject arbitrary HTML/JavaScript that executes in the victim's browser when they encounter an HTML error page generated by Slim.\n\nThe vulnerability is present even with `displayErrorDetails = false` as the unescaped title and description are rendered on this error path.\n\nBuilt-in exceptions (`HttpNotFoundException`, `HttpBadRequestException`, etc.) ship plain-text defaults, so a vanilla Slim app with no user code is not exploitable. Only applications that feed untrusted data into `setTitle()` and/or `setDescription()` are affected.\n\n### Patches\n\nThe issue is fixed in 4.15.2.\n\n### Workarounds\n\nWithout upgrading, applications can:\n\n- Avoid passing untrusted/request-derived data into `HttpException::setTitle()` and `setDescription()`. Use static, plain-text error copy instead.\n- Register a custom error renderer (an `ErrorRendererInterface` implementation, or a subclass of `HtmlErrorRenderer` that escapes the title and description) for the HTML media type.\n\n### Acknowledgments\n\nSlim is grateful to and thanks GitHub user [0xEr3n](https://github.com/0xEr3n) for reporting this issue.\n\n### Resources\n\n- CWE-79: https://cwe.mitre.org/data/definitions/79.html","aliases":["CVE-2026-48157"],"modified":"2026-09-10T03:50:48.274978408Z","published":"2026-06-23T21:54:06Z","database_specific":{"nvd_published_at":"2026-06-15T22:16:17Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-23T21:54:06Z"},"references":[{"type":"WEB","url":"https://github.com/slimphp/Slim/security/advisories/GHSA-53h4-8rc4-f539"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48157"},{"type":"PACKAGE","url":"https://github.com/slimphp/Slim"},{"type":"WEB","url":"https://github.com/slimphp/Slim/releases/tag/4.15.2"}],"affected":[{"package":{"name":"slim/slim","ecosystem":"Packagist","purl":"pkg:composer/slim/slim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.4.0"},{"fixed":"4.15.2"}]}],"versions":["4.10.0","4.11.0","4.12.0","4.13.0","4.14.0","4.15.0","4.15.1","4.4.0","4.5.0","4.6.0","4.7.0","4.7.1","4.8.0","4.8.1","4.9.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 4.15.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-53h4-8rc4-f539/GHSA-53h4-8rc4-f539.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}