{"id":"CVE-2026-49211","title":"symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil","summary":"symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil","severity":"medium","cwe":["CWE-200"],"vendor":"symfony","product":"symfony/ux-autocomplete","affected":["symfony/ux-autocomplete >= 2.2.0, < 2.36.0","symfony/ux-autocomplete >= 3.0.0, < 3.1.0"],"patched":["symfony/ux-autocomplete 2.36.0","symfony/ux-autocomplete 3.1.0"],"published":"2026-06-19","updated":"2026-06-19","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-946h-jp5c-8fvh","references":[{"url":"https://github.com/symfony/ux/security/advisories/GHSA-946h-jp5c-8fvh"},{"url":"https://github.com/symfony/ux/commit/725ab3d40689c91ff19ad2d01940a30007769214"},{"url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/ux-autocomplete/CVE-2026-49211.yaml"},{"url":"https://github.com/advisories/GHSA-946h-jp5c-8fvh"}],"tags":["ghsa","composer"],"ingestedAt":"2026-06-22T15:52:21.064Z","ecosystem":"composer","epss":0.00531,"epssPercentile":0.43842,"slug":"CVE-2026-49211","body":"## Overview\n\n### Description\n\n`Symfony\\UX\\Autocomplete\\Doctrine\\EntitySearchUtil::addSearchClause()` builds the `LIKE` expression used by the autocomplete endpoint by wrapping the client-supplied query in `%...%` without escaping the SQL `LIKE` wildcards (`%`, `_`, `\\`). The value is passed as a bound parameter, so this is not SQL injection, but a client can send `%` to match every row or use `_` as a single-character wildcard.\n\nBecause `searchable_fields` defaults to every property of the entity and the autocomplete endpoint is public by default (`BaseEntityAutocompleteType` ships with `security => false`), an unauthenticated user can turn the endpoint into a broad matcher or a blind boolean oracle against every column of the entity, including columns the application never intended to expose.\n\n### Resolution\n\n`EntitySearchUtil` now escapes `\\`, `%`, and `_` in the user-supplied query with `addcslashes()` and appends an explicit `ESCAPE '\\'` clause to the generated `LIKE` expression, so those characters are matched literally. The exact-match `words_query` `IN()` branch is unchanged.\n\nThe patch for this issue is available [here](https://github.com/symfony/ux/commit/725ab3d40689c91ff19ad2d01940a30007769214) for branch 2.x (and forward-ported to 3.x).\n\n### Credits\n\nSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix.\n\n## Affected packages\n\n- `symfony/ux-autocomplete >= 2.2.0, < 2.36.0`\n- `symfony/ux-autocomplete >= 3.0.0, < 3.1.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `symfony/ux-autocomplete 2.36.0`\n- `symfony/ux-autocomplete 3.1.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}