{"id":"GHSA-2wwr-9x6f-88gp","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2wwr-9x6f-88gp","summary":"EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components","details":"EasyAdminBundle ships two public Twig components — `<twig:ea:Flag countryCode=\"...\">` and `<twig:ea:Icon name=\"...\">` — that load SVG files from disk using a path built directly from a public component property, and then render the resulting markup with the Twig `|raw` filter.\n\nWhen an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:\n\n- Arbitrary `.svg` file disclosure (both components) — the property value is concatenated into a filesystem path without normalizing or constraining it, so `..` segments are preserved and resolved by PHP. Any file on the server whose absolute path ends in `.svg` (for example, user-uploaded SVG icons stored elsewhere on the host) can be read and embedded into the rendered page.\n- Reflected XSS in the admin UI (Flag component only) — when the requested flag file does not exist, the Flag component falls back to a hard-coded SVG string that interpolates the raw `countryCode` value twice, and the parent template renders that string with `|raw`. An attacker who controls `countryCode` can therefore inject arbitrary HTML/JavaScript that will execute inside the authenticated admin context that rendered the component.\n\nThe first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through `Symfony\\Component\\Intl\\Countries` to the `Flag` component, and only hard-coded `internal:..` names or values previously set in PHP via `MenuItem::setIcon()` to the `Icon` component. The vulnerability is reachable only in third-party templates that pass attacker-controlled data into these properties.\n\n### Impact\n\nPath traversal is information disclosure bounded by the `.svg` extension; reflected XSS in Flag runs in the admin context and is therefore more sensitive but requires a vulnerable template wiring and user interaction.\n\n### Affected components\n\n- `EasyCorp\\Bundle\\EasyAdminBundle\\Twig\\Component\\Flag` — public Twig tag `<twig:ea:Flag>`, property `countryCode`.\n- `EasyCorp\\Bundle\\EasyAdminBundle\\Twig\\Component\\Icon` — public Twig tag `<twig:ea:Icon>`, property `name` when the value starts with the `internal:` prefix.\n\n### Credit\n\nEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix.","published":"2026-07-01T18:18:46Z","modified":"2026-07-01T18:30:09.146550162Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"easycorp/easyadmin-bundle","fixedVersion":"4.29.10"},{"ecosystem":"Packagist","name":"easycorp/easyadmin-bundle","fixedVersion":"5.0.10"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/EasyCorp/EasyAdminBundle/security/advisories/GHSA-2wwr-9x6f-88gp"},{"type":"PACKAGE","url":"https://github.com/EasyCorp/EasyAdminBundle"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-01T18:30:09.146550162Z"}}