Medium severity5.4NVD Advisory· Published Jul 17, 2026· Updated Jul 21, 2026
CVE-2026-49216
CVE-2026-49216
Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX response items in _createAutocompleteWithRemoteData() by interpolating the text field into HTML template literals (${item[labelField]}) rather than text, allowing attacker-controlled markup from user-supplied dropdown values to execute in the browser of any user who opens an autocomplete widget backed by the same data. This issue is fixed in versions 2.36.0 and 3.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
symfony/ux-autocompletePackagist | >= 2.2.0, < 2.36.0 | 2.36.0 |
symfony/ux-autocompletePackagist | >= 3.0.0, < 3.1.0 | 3.1.0 |
Affected products
42.2.0 - 3.1.0+ 2 more
- (no CPE)range: 2.2.0 - 3.1.0
- cpe:2.3:a:symfony:ux:*:*:*:*:*:*:*:*range: >=2.2.0,<2.36.0
- cpe:2.3:a:symfony:ux:3.0.0:*:*:*:*:*:*:*
- Range: 2.2.0 - 3.1.0
Patches
Vulnerability mechanics
References
6- github.com/symfony/ux/commit/842ae54bc74de389299f975f01aafae272cb0019nvdPatchWEB
- github.com/advisories/GHSA-mwqm-4fw3-cjvrghsaADVISORY
- github.com/symfony/ux/security/advisories/GHSA-mwqm-4fw3-cjvrnvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/symfony/ux-autocomplete/CVE-2026-49216.yamlghsaWEB
- github.com/symfony/ux/releases/tag/v2.36.0nvdRelease Notes
- github.com/symfony/ux/releases/tag/v3.1.0nvdRelease Notes
News mentions
0No linked articles in our index yet.