{"id":"CVE-2026-55878","aliases":["GHSA-p9xj-fpr2-jf2q"],"url":"https://o3.security/vulnerability/CVE-2026-55878","summary":"Symfony: Path Traversal in symfony/ux-toolkit Allows Arbitrary File Write and Read via Crafted Recipe Manifest","details":"### Description\nThe `ux:install` console command installs files from a recipe kit by copying paths listed in a `copy-files` map. The only guard against malicious paths was `Path::isRelative()`, which returns `true` for paths like `../../../etc`. `Path::join()` then resolves the `..` segments without complaint, so the final path can escape the intended directory entirely. A crafted or compromised kit can therefore write attacker-controlled content   to arbitrary locations on the developer's machine or CI runner.\n\nBecause the copy operation creates missing parent directories and can overwrite existing files silently (with   `--force` or in non-interactive environments), an attacker who controls a kit can overwrite files such as controllers, git hooks, or `.env` to achieve code execution. The source side of `copy-files` is symmetrically   affected, enabling local file reads outside the recipe directory.\n\n### Resolution\n\nThe fix introduces an `Assert::pathDoesNotEscapeDirectory()` helper that rejects any `copy-files` source or destination path containing a `..` segment, regardless of whether `/` or `\\` is used as the separator. This check is enforced in both `RecipeManifest` (which also guards the source Finder) and `File`. As a last line of defense, the installer re-verifies the fully resolved paths with `Path::isBasePath()` immediately before each filesystem read and write.\n\n### Credits\n\nSymfony would like to thank Pascal Cescon for reporting the issue and Hugo Alliaume for providing the fix.","published":"2026-07-08T21:30:33.816Z","modified":"2026-08-12T03:51:48.918978663Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.00192,"percentile":0.09023,"asOf":"2026-09-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"symfony/ux-toolkit","fixedVersion":"2.36.1"},{"ecosystem":"Packagist","name":"symfony/ux-toolkit","fixedVersion":"3.2.0"}],"fix":{"url":"https://github.com/symfony/ux/commit/7b4ddf3764bf269a1b5fde5bf03c4bce568694e4","label":"symfony/ux@7b4ddf3"},"references":[{"type":"WEB","url":"https://github.com/symfony/ux/releases/tag/v2.36.1"},{"type":"WEB","url":"https://github.com/symfony/ux/releases/tag/v3.2.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55878.json"},{"type":"ADVISORY","url":"https://github.com/symfony/ux/security/advisories/GHSA-p9xj-fpr2-jf2q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55878"},{"type":"FIX","url":"https://github.com/symfony/ux/commit/7b4ddf3764bf269a1b5fde5bf03c4bce568694e4"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/ux-toolkit/CVE-2026-55878.yaml"},{"type":"PACKAGE","url":"https://github.com/symfony/ux"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.918978663Z"}}