VYPR
High severity7.8NVD Advisory· Published Jul 8, 2026· Updated Jul 10, 2026

CVE-2026-55878

CVE-2026-55878

Description

Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install console command installs files from a recipe kit by copying paths listed in a copy-files map, and because Path::isRelative() accepts paths like ../../../etc, a crafted or compromised kit can write attacker-controlled content to arbitrary locations or read local files outside the recipe directory. This issue is fixed in versions 2.36.1 and 3.2.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
symfony/ux-toolkitPackagist
>= 2.32.0, < 2.36.12.36.1
symfony/ux-toolkitPackagist
>= 3.0.0, < 3.2.03.2.0

Affected products

1
  • Sensiolabs/UXllm-create
    Range: 2.32.0 < 2.36.1, 3.0.0 < 3.2.0

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.