{"id":"GHSA-x5qj-865h-mgvm","summary":"Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes","details":"### Description\n\n`Symfony\\Component\\HtmlSanitizer\\Visitor\\AttributeSanitizer\\UrlAttributeSanitizer::getSupportedAttributes()` enumerates the attribute names whose values are scrubbed through `UrlSanitizer::sanitize()` (scheme and host allow-lists, `javascript:` rejection, BiDi check, etc.). The list is `['src', 'href', 'lowsrc', 'background', 'ping', 'action', 'formaction', 'poster', 'cite']`. Other URL-bearing attributes are absent: `\u003cobject data=…\u003e`, `\u003capplet codebase=…\u003e`, `\u003capplet archive=…\u003e` and `\u003cobject archive=…\u003e`, `\u003ciframe longdesc=…\u003e` and `\u003cimg longdesc=…\u003e`. When an integrator opts these elements/attributes in via `allowElement('object', ['data'])`, `allowElement('applet', ['codebase'])`, etc., or via `allowAttribute()`, no URL sanitization runs: `data=\"javascript:alert(1)\"` and similar payloads ship through unchanged into the output, enabling stored XSS.\n\n`\u003cmeta http-equiv=\"refresh\" content=\"0; url=…\"\u003e` is the same class of bug routed differently: the URL is embedded inside a multi-field `content` attribute that the per-attribute sanitizer cannot detect from the attribute name alone. Integrators who enable `\u003cmeta\u003e` with the `content` attribute (e.g. via `allowStaticElements()`) see `content=\"0; url=javascript:alert(1)\"` pass through, producing a refresh-driven navigation to a `javascript:` URL.\n\nDefault configurations are not affected: `\u003cobject\u003e`, `\u003capplet\u003e` and `\u003ciframe\u003e` are not in `W3CReference::BODY_ELEMENTS` and `\u003cmeta\u003e` requires an explicit opt-in to `\u003chead\u003e` context. The vulnerability surface is integrators who explicitly allow any of those elements together with the listed URL-bearing attributes.\n\n### Resolution\n\n`UrlAttributeSanitizer` now also routes `data`, `codebase`, `archive` and `longdesc` through `UrlSanitizer::sanitize()`. A new `MetaRefreshAttributeSanitizer` registered as a default attribute sanitizer detects the `\u003cdelay\u003e; url=\u003curl\u003e` syntax inside `\u003cmeta content\u003e`, sanitizes the embedded URL, and drops the attribute if the URL is rejected; non-refresh meta `content` values are passed through unchanged.\n\nThe patches for this issue are available [here](https://github.com/symfony/symfony/commit/069a70f9f26e61e9de3b7f9a864a86ed24b36bd0) for branch 6.4 (and forward-ported to 7.4, 8.0 and 8.1).\n\n### Credits\n\nSymfony would like to thank Scott Arciszewski (Trail of Bits) for reporting the issue and Nicolas Grekas for providing the fix.","aliases":["CVE-2026-48761"],"modified":"2026-09-10T03:50:51.216603592Z","published":"2026-06-15T16:46:53Z","database_specific":{"cwe_ids":["CWE-1023","CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-15T16:46:53Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/symfony/symfony/security/advisories/GHSA-x5qj-865h-mgvm"},{"type":"WEB","url":"https://github.com/symfony/symfony/commit/069a70f9f26e61e9de3b7f9a864a86ed24b36bd0"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/html-sanitizer/CVE-2026-48761.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2026-48761.yaml"},{"type":"PACKAGE","url":"https://github.com/symfony/symfony"},{"type":"WEB","url":"https://symfony.com/cve-2026-48761"}],"affected":[{"package":{"name":"symfony/html-sanitizer","ecosystem":"Packagist","purl":"pkg:composer/symfony/html-sanitizer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.1.0"},{"fixed":"6.4.41"}]}],"versions":["v6.1.0","v6.1.11","v6.1.9","v6.2.0","v6.2.0-BETA1","v6.2.0-RC1","v6.2.2","v6.2.5","v6.2.7","v6.3.0","v6.3.0-BETA1","v6.3.0-RC1","v6.3.12","v6.3.4","v6.3.7","v6.4.0","v6.4.0-BETA1","v6.4.0-BETA2","v6.4.0-RC1","v6.4.12","v6.4.13","v6.4.17","v6.4.18","v6.4.21","v6.4.24","v6.4.25","v6.4.28","v6.4.3","v6.4.35","v6.4.4","v6.4.40","v6.4.7","v6.4.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-x5qj-865h-mgvm/GHSA-x5qj-865h-mgvm.json"}},{"package":{"name":"symfony/html-sanitizer","ecosystem":"Packagist","purl":"pkg:composer/symfony/html-sanitizer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.4.13"}]}],"versions":["v7.0.0","v7.0.3","v7.0.4","v7.0.7","v7.0.8","v7.1.0","v7.1.0-BETA1","v7.1.0-RC1","v7.1.1","v7.1.10","v7.1.11","v7.1.5","v7.1.6","v7.2.0","v7.2.0-BETA1","v7.2.0-RC1","v7.2.2","v7.2.3","v7.2.6","v7.2.9","v7.3.0","v7.3.0-BETA1","v7.3.0-RC1","v7.3.2","v7.3.3","v7.3.6","v7.4.0","v7.4.0-BETA1","v7.4.0-BETA2","v7.4.0-RC1","v7.4.12","v7.4.7","v7.4.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-x5qj-865h-mgvm/GHSA-x5qj-865h-mgvm.json"}},{"package":{"name":"symfony/html-sanitizer","ecosystem":"Packagist","purl":"pkg:composer/symfony/html-sanitizer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.0.13"}]}],"versions":["v8.0.0","v8.0.12","v8.0.7","v8.0.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-x5qj-865h-mgvm/GHSA-x5qj-865h-mgvm.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.1.0"},{"fixed":"6.4.41"}]}],"versions":["v6.1.0","v6.1.1","v6.1.10","v6.1.11","v6.1.12","v6.1.2","v6.1.3","v6.1.4","v6.1.5","v6.1.6","v6.1.7","v6.1.8","v6.1.9","v6.2.0","v6.2.0-BETA1","v6.2.0-BETA2","v6.2.0-BETA3","v6.2.0-RC1","v6.2.0-RC2","v6.2.1","v6.2.10","v6.2.11","v6.2.12","v6.2.13","v6.2.14","v6.2.2","v6.2.3","v6.2.4","v6.2.5","v6.2.6","v6.2.7","v6.2.8","v6.2.9","v6.3.0","v6.3.0-BETA1","v6.3.0-BETA2","v6.3.0-BETA3","v6.3.0-RC1","v6.3.0-RC2","v6.3.1","v6.3.10","v6.3.11","v6.3.12","v6.3.2","v6.3.3","v6.3.4","v6.3.5","v6.3.6","v6.3.7","v6.3.8","v6.3.9","v6.4.0","v6.4.0-BETA1","v6.4.0-BETA2","v6.4.0-BETA3","v6.4.0-RC1","v6.4.0-RC2","v6.4.1","v6.4.10","v6.4.11","v6.4.12","v6.4.13","v6.4.14","v6.4.15","v6.4.16","v6.4.17","v6.4.18","v6.4.19","v6.4.2","v6.4.20","v6.4.21","v6.4.22","v6.4.23","v6.4.24","v6.4.25","v6.4.26","v6.4.27","v6.4.28","v6.4.29","v6.4.3","v6.4.30","v6.4.31","v6.4.32","v6.4.33","v6.4.34","v6.4.35","v6.4.36","v6.4.37","v6.4.38","v6.4.39","v6.4.4","v6.4.40","v6.4.5","v6.4.6","v6.4.7","v6.4.8","v6.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-x5qj-865h-mgvm/GHSA-x5qj-865h-mgvm.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.4.13"}]}],"versions":["v7.0.0","v7.0.1","v7.0.10","v7.0.2","v7.0.3","v7.0.4","v7.0.5","v7.0.6","v7.0.7","v7.0.8","v7.0.9","v7.1.0","v7.1.0-BETA1","v7.1.0-RC1","v7.1.1","v7.1.10","v7.1.11","v7.1.2","v7.1.3","v7.1.4","v7.1.5","v7.1.6","v7.1.7","v7.1.8","v7.1.9","v7.2.0","v7.2.0-BETA1","v7.2.0-BETA2","v7.2.0-RC1","v7.2.1","v7.2.2","v7.2.3","v7.2.4","v7.2.5","v7.2.6","v7.2.7","v7.2.8","v7.2.9","v7.3.0","v7.3.0-BETA1","v7.3.0-BETA2","v7.3.0-RC1","v7.3.1","v7.3.10","v7.3.11","v7.3.2","v7.3.3","v7.3.4","v7.3.5","v7.3.6","v7.3.7","v7.3.8","v7.3.9","v7.4.0","v7.4.0-BETA1","v7.4.0-BETA2","v7.4.0-RC1","v7.4.0-RC2","v7.4.0-RC3","v7.4.1","v7.4.10","v7.4.11","v7.4.12","v7.4.2","v7.4.3","v7.4.4","v7.4.5","v7.4.6","v7.4.7","v7.4.8","v7.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-x5qj-865h-mgvm/GHSA-x5qj-865h-mgvm.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.0.13"}]}],"versions":["v8.0.0","v8.0.1","v8.0.10","v8.0.11","v8.0.12","v8.0.2","v8.0.3","v8.0.4","v8.0.5","v8.0.6","v8.0.7","v8.0.8","v8.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-x5qj-865h-mgvm/GHSA-x5qj-865h-mgvm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}