Security Advisory

CVE-2026-49216

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-17 16:15:34
Last updated 2026-07-21 01:44:13
Assigner GitHub_M
CVSS score 5.1
State PUBLISHED

Description

Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX response items in _createAutocompleteWithRemoteData() by interpolating the text field into HTML template literals (<div>${item[labelField]}</div>) rather than text, allowing attacker-controlled markup from user-supplied dropdown values to execute in the browser of any user who opens an autocomplete widget backed by the same data. This issue is fixed in versions 2.36.0 and 3.1.0.