{"id":"CVE-2026-55877","title":"symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses","summary":"symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses","severity":"medium","cvss":6.1,"cwe":["CWE-79"],"vendor":"symfony","product":"symfony/ux-icons","ecosystem":"composer","affected":["symfony/ux-icons >= 2.17.0, < 2.36.1","symfony/ux-icons >= 3.0.0, < 3.2.0"],"patched":["symfony/ux-icons 2.36.1","symfony/ux-icons 3.2.0"],"published":"2026-06-19","updated":"2026-06-19","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-6v8j-33hc-mv84","references":[{"url":"https://github.com/symfony/ux/security/advisories/GHSA-6v8j-33hc-mv84"},{"url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/ux-icons/CVE-2026-55877.yaml"},{"url":"https://github.com/advisories/GHSA-6v8j-33hc-mv84"}],"tags":["ghsa","composer"],"ingestedAt":"2026-06-22T13:35:24.276Z","epss":0.00338,"epssPercentile":0.27332,"slug":"CVE-2026-55877","body":"## Overview\n\n### Description\n\nThe `ux_icon()` Twig function is marked `is_safe=['html']`, so Twig never escapes its output. `Icon::toHtml()` inlines the SVG source verbatim into the page. Browsers execute `<script>` elements and `on*` event-handler attributes found inside inline SVG, making any unsanitized icon a vector for cross-site scripting.\n\nTwo code paths were affected. In the local file path, `Icon::fromFile()` only stripped `<script>` elements that were direct children of `<svg>`, leaving nested scripts and all `on*` attributes untouched despite a code comment claiming broader protection. In the Iconify on-demand path (enabled by default), the remote JSON `body` field was wrapped into an `Icon` object with no sanitization at all. Concrete attack vectors include a malicious SVG icon pack from a third-party theme or downloaded icon set, or a controlled Iconify endpoint configured via `iconify.endpoint` (including a poisoned cache).\n\n### Resolution\n\nIntroducing an `IconFactory` that centralizes sanitization across every icon source before an `Icon` object is created. The sanitizer removes script-capable elements (`script`, `foreignObject`, `iframe`, `object`, `embed`), SMIL animations targeting `on*`, `href`, or `xlink:href` attributes, CDATA sections, processing instructions, all `on*` attributes, and `javascript:`, `vbscript:`, and `data:text/html` URL schemes. \n`<style>` elements are kept for theming but have any handlers stripped. Icons that contain none of these constructs are byte-for-byte identical after sanitization. \n\n### Credits\n\nSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix.\n\n## Affected packages\n\n- `symfony/ux-icons >= 2.17.0, < 2.36.1`\n- `symfony/ux-icons >= 3.0.0, < 3.2.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `symfony/ux-icons 2.36.1`\n- `symfony/ux-icons 3.2.0`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}