CVE-2026-49210
Severity CVSS v4.0:
LOW
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
17/07/2026
Last modified:
20/07/2026
Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml() interpolates the client-controlled children[id].tag value from LiveComponentSubscriber and InterceptChildComponentRenderSubscriber directly into HTML as a tag name without escaping or validation, allowing arbitrary HTML, including tags, on any Live Component re-render that contains at least one child component. This issue is fixed in versions 2.36.0 and 3.1.0.
Impact
Base Score 4.0
2.30
Severity 4.0
LOW
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:symfony:ux:*:*:*:*:*:*:*:* | 2.8.0 (including) | 2.36.0 (excluding) |
| cpe:2.3:a:symfony:ux:3.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



