CVE-2026-49210: Symfony UX: XSS in symfony/ux-live-component via attacker-controlled child component tag
Description
Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml() interpolates the $childTag argument directly into the HTML output as a tag name, without escaping or validation. The value originates from client-controlled JSON (children[id].tag) parsed by LiveComponentSubscriber and propagated through InterceptChildComponentRenderSubscriber, so an attacker who can reach the Live Component endpoint can inject arbitrary HTML, including <script> tags, on any re-render of a Live Component that contains at least one child component.
In the default configuration, the Live Component endpoint is gated by an Accept: application/vnd.live-component+html request-header check that cannot be set cross-origin without a CORS preflight, so the issue is primarily a defense-in-depth gap. It becomes directly exploitable on applications that have relaxed CORS to allow this header from untrusted origins, or that have been pivoted from another same-origin XSS.
Resolution
ChildComponentPartialRenderer now validates $childTag against a strict HTML tag-name regex before interpolating it, and rejects any value that doesn't match. Anything that wouldn't be a valid HTML tag is dropped before reaching the response.
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x).
Credits
Symfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix.
Other sources
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml() interpolates the client-controlled children[id].tag value from LiveComponentSubscriber and InterceptChildComponentRenderSubscriber directly into HTML as a tag name without escaping or validation, allowing arbitrary HTML, including <script> tags, on any Live Component re-render that contains at least one child component. This issue is fixed in versions 2.36.0 and 3.1.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/symfony/ux-live-componentto a version that resolves this vulnerability.Fixed in 3.1.0 - Upgrade
Upgrade
composer/symfony/ux-live-componentto a version that resolves this vulnerability.Fixed in 2.36.0 - Upgrade
Upgrade
Symfony UX live-component (symfony/ux-live-component)to a version that resolves this vulnerability.Fixed in 2.36.0 - Upgrade
Upgrade
Symfony UX live-component (symfony/ux-live-component)to a version that resolves this vulnerability.Fixed in 3.1.0 - Compensating control
Keep the Live Component endpoint gated by the `Accept: application/vnd.live-component+html` request-header check, and avoid relaxing CORS to allow this header from untrusted origins (otherwise the attacker can reach the Live Component endpoint and inject arbitrary HTML via attacker-controlled `children[id].tag`).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49210?
The severity of CVE-2026-49210 is classified as low with a CVSS score of 4.0.
What does CVE-2026-49210 exploit?
CVE-2026-49210 exploits a cross-site scripting (XSS) vulnerability in Symfony UX through attacker-controlled child component tags.
How do I fix CVE-2026-49210?
To fix CVE-2026-49210, update to the latest version of symfony/ux-live-component where the vulnerability has been addressed.
What is affected by CVE-2026-49210?
CVE-2026-49210 affects versions of composer/symfony/ux-live-component that allow unvalidated input to create HTML output.
Is CVE-2026-49210 a high-risk vulnerability?
CVE-2026-49210 is not considered high-risk due to its low severity rating, but it still poses a potential XSS threat.