CVE-2025-47946
unknown
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
โ
Description
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
Predictions
Exploit likelihood
30%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | symfony/ux-twig-component | <2.25.1 | 2.25.1 |
| Packagist | symfony/ux-live-component | <2.25.1 | 2.25.1 |
References
- https://github.com/symfony/ux/security/advisories/GHSA-5j3w-5pcr-f8hg
- https://nvd.nist.gov/vuln/detail/CVE-2025-47946
- https://github.com/symfony/ux-live-component/commit/7ad44cf56d750b9f56658ed986286a10da132ee7
- https://github.com/symfony/ux-twig-component/commit/b5d4e77db69315aeb18d2238e0e7c943d340ce76
- https://github.com/symfony/ux/commit/b5d1c85995c128cb926d47a96cfbfbd500b643a8
- https://github.com/symfony/ux/commit/c2f7738ee0969c31df7514025a7f5fc6e153932d
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/ux-live-component/CVE-2025-47946.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/ux-twig-component/CVE-2025-47946.yaml
- https://github.com/symfony/ux
- https://symfony.com/blog/symfony-ux-cve-2025-47946-unsanitized-html-attribute-injection-via-componentattributes
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.