---
id: CVE-2026-55877
title: >-
  symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify
  on-demand responses
summary: >-
  symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify
  on-demand responses
severity: medium
cvss: 6.1
cwe:
  - CWE-79
vendor: symfony
product: symfony/ux-icons
ecosystem: composer
affected:
  - 'symfony/ux-icons >= 2.17.0, < 2.36.1'
  - 'symfony/ux-icons >= 3.0.0, < 3.2.0'
patched:
  - symfony/ux-icons 2.36.1
  - symfony/ux-icons 3.2.0
published: '2026-06-19'
updated: '2026-06-19'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-6v8j-33hc-mv84'
references:
  - url: 'https://github.com/symfony/ux/security/advisories/GHSA-6v8j-33hc-mv84'
  - url: >-
      https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/ux-icons/CVE-2026-55877.yaml
  - url: 'https://github.com/advisories/GHSA-6v8j-33hc-mv84'
tags:
  - ghsa
  - composer
ingestedAt: '2026-06-22T13:35:24.276Z'
epss: 0.00338
epssPercentile: 0.24423
---

## Overview

### Description

The `ux_icon()` Twig function is marked `is_safe=['html']`, so Twig never escapes its output. `Icon::toHtml()` inlines the SVG source verbatim into the page. Browsers execute `<script>` elements and `on*` event-handler attributes found inside inline SVG, making any unsanitized icon a vector for cross-site scripting.

Two code paths were affected. In the local file path, `Icon::fromFile()` only stripped `<script>` elements that were direct children of `<svg>`, leaving nested scripts and all `on*` attributes untouched despite a code comment claiming broader protection. In the Iconify on-demand path (enabled by default), the remote JSON `body` field was wrapped into an `Icon` object with no sanitization at all. Concrete attack vectors include a malicious SVG icon pack from a third-party theme or downloaded icon set, or a controlled Iconify endpoint configured via `iconify.endpoint` (including a poisoned cache).

### Resolution

Introducing an `IconFactory` that centralizes sanitization across every icon source before an `Icon` object is created. The sanitizer removes script-capable elements (`script`, `foreignObject`, `iframe`, `object`, `embed`), SMIL animations targeting `on*`, `href`, or `xlink:href` attributes, CDATA sections, processing instructions, all `on*` attributes, and `javascript:`, `vbscript:`, and `data:text/html` URL schemes. 
`<style>` elements are kept for theming but have any handlers stripped. Icons that contain none of these constructs are byte-for-byte identical after sanitization. 

### Credits

Symfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix.

## Affected packages

- `symfony/ux-icons >= 2.17.0, < 2.36.1`
- `symfony/ux-icons >= 3.0.0, < 3.2.0`

## Remediation

Upgrade to a patched release:

- `symfony/ux-icons 2.36.1`
- `symfony/ux-icons 3.2.0`
