{"id":"GHSA-p9xj-fpr2-jf2q","summary":"symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest","details":"### Description\nThe `ux:install` console command installs files from a recipe kit by copying paths listed in a `copy-files` map. The only guard against malicious paths was `Path::isRelative()`, which returns `true` for paths like `../../../etc`. `Path::join()` then resolves the `..` segments without complaint, so the final path can escape the intended directory entirely. A crafted or compromised kit can therefore write attacker-controlled content   to arbitrary locations on the developer's machine or CI runner.\n\nBecause the copy operation creates missing parent directories and can overwrite existing files silently (with   `--force` or in non-interactive environments), an attacker who controls a kit can overwrite files such as controllers, git hooks, or `.env` to achieve code execution. The source side of `copy-files` is symmetrically   affected, enabling local file reads outside the recipe directory.\n\n### Resolution\n\nThe fix introduces an `Assert::pathDoesNotEscapeDirectory()` helper that rejects any `copy-files` source or destination path containing a `..` segment, regardless of whether `/` or `\\` is used as the separator. This check is enforced in both `RecipeManifest` (which also guards the source Finder) and `File`. As a last line of defense, the installer re-verifies the fully resolved paths with `Path::isBasePath()` immediately before each filesystem read and write.\n\n### Credits\n\nSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix.","aliases":["CVE-2026-55878"],"modified":"2026-09-10T03:51:09.315334404Z","published":"2026-06-19T21:42:18Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-19T21:42:18Z","nvd_published_at":null,"cwe_ids":["CWE-22"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/symfony/ux/security/advisories/GHSA-p9xj-fpr2-jf2q"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/ux-toolkit/CVE-2026-55878.yaml"},{"type":"PACKAGE","url":"https://github.com/symfony/ux"}],"affected":[{"package":{"name":"symfony/ux-toolkit","ecosystem":"Packagist","purl":"pkg:composer/symfony/ux-toolkit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.32.0"},{"fixed":"2.36.1"}]}],"versions":["v2.32.0","v2.33.0","v2.34.0","v2.35.0","v2.36.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-p9xj-fpr2-jf2q/GHSA-p9xj-fpr2-jf2q.json"}},{"package":{"name":"symfony/ux-toolkit","ecosystem":"Packagist","purl":"pkg:composer/symfony/ux-toolkit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.2.0"}]}],"versions":["v3.0.0","v3.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-p9xj-fpr2-jf2q/GHSA-p9xj-fpr2-jf2q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}