Vulnerability Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX response items in _createAutocompleteWithRemoteData() by interpolating the text field into HTML template literals (<div>${item[labelField]}</div>) rather than text, allowing attacker-controlled markup from user-supplied dropdown values to execute in the browser of any user who opens an autocomplete widget backed by the same data. This issue is fixed in versions 2.36.0 and 3.1.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symfony | Ux | >= 2.2.0, < 2.36.0 |
Related Weaknesses (CWE)
References
- https://github.com/symfony/ux/commit/842ae54bc74de389299f975f01aafae272cb0019Patch
- https://github.com/symfony/ux/releases/tag/v2.36.0Release Notes
- https://github.com/symfony/ux/releases/tag/v3.1.0Release Notes
- https://github.com/symfony/ux/security/advisories/GHSA-mwqm-4fw3-cjvrVendor Advisory
FAQ
What is CVE-2026-49216?
CVE-2026-49216 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX response items in _createAutocompleteWithRemoteData...
How severe is CVE-2026-49216?
CVE-2026-49216 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-49216?
Check the references section above for vendor advisories and patch information. Affected products include: Symfony Ux.