Flux
Toutes les sources

Symfony Blog

127 articles Flux RSS
Programmation Web
CVE-2026-49210: XSS in symfony/ux-live-component via attacker-controlled child component tag

CVE-2026-49210: XSS in symfony/ux-live-component via attacker-controlled child component tag

Affected versions Symfony versions >=2.8.0, =3.0.0, <3.1.0 of the Symfony UX Live Component component are affected by this security issue. The issue has been fixed in Symfony 2.36.0, 3.1.0. Description Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml()…

Symfony Blog