{"id":"GHSA-6v8j-33hc-mv84","summary":"symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses","details":"### Description\n\nThe `ux_icon()` Twig function is marked `is_safe=['html']`, so Twig never escapes its output. `Icon::toHtml()` inlines the SVG source verbatim into the page. Browsers execute `\u003cscript\u003e` elements and `on*` event-handler attributes found inside inline SVG, making any unsanitized icon a vector for cross-site scripting.\n\nTwo code paths were affected. In the local file path, `Icon::fromFile()` only stripped `\u003cscript\u003e` elements that were direct children of `\u003csvg\u003e`, leaving nested scripts and all `on*` attributes untouched despite a code comment claiming broader protection. In the Iconify on-demand path (enabled by default), the remote JSON `body` field was wrapped into an `Icon` object with no sanitization at all. Concrete attack vectors include a malicious SVG icon pack from a third-party theme or downloaded icon set, or a controlled Iconify endpoint configured via `iconify.endpoint` (including a poisoned cache).\n\n### Resolution\n\nIntroducing an `IconFactory` that centralizes sanitization across every icon source before an `Icon` object is created. The sanitizer removes script-capable elements (`script`, `foreignObject`, `iframe`, `object`, `embed`), SMIL animations targeting `on*`, `href`, or `xlink:href` attributes, CDATA sections, processing instructions, all `on*` attributes, and `javascript:`, `vbscript:`, and `data:text/html` URL schemes. \n`\u003cstyle\u003e` elements are kept for theming but have any handlers stripped. Icons that contain none of these constructs are byte-for-byte identical after sanitization. \n\n### Credits\n\nSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix.","aliases":["CVE-2026-55877"],"modified":"2026-09-10T03:51:08.052739946Z","published":"2026-06-19T21:42:15Z","database_specific":{"github_reviewed_at":"2026-06-19T21:42:15Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/symfony/ux/security/advisories/GHSA-6v8j-33hc-mv84"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/ux-icons/CVE-2026-55877.yaml"},{"type":"PACKAGE","url":"https://github.com/symfony/ux"}],"affected":[{"package":{"name":"symfony/ux-icons","ecosystem":"Packagist","purl":"pkg:composer/symfony/ux-icons"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.17.0"},{"fixed":"2.36.1"}]}],"versions":["v2.17.0","v2.18.0","v2.18.1","v2.19.0","v2.20.0","v2.21.0","v2.22.0","v2.22.1","v2.23.0","v2.24.0","v2.25.0","v2.26.0","v2.27.0","v2.28.0","v2.28.2","v2.29.0","v2.29.2","v2.30.0","v2.31.0","v2.32.0","v2.33.0","v2.34.0","v2.35.0","v2.36.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6v8j-33hc-mv84/GHSA-6v8j-33hc-mv84.json"}},{"package":{"name":"symfony/ux-icons","ecosystem":"Packagist","purl":"pkg:composer/symfony/ux-icons"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.2.0"}]}],"versions":["v3.0.0","v3.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6v8j-33hc-mv84/GHSA-6v8j-33hc-mv84.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}