
Two Symfony UX CVEs, patch now. → CVE-2026-55877: ux_icon() renders unsanitized SVG → XSS → CVE-2026-55878: path traversal in Toolkit installer Upgrade to UX 3.2.0 or 2.36.1.
Post summary
The advisory highlights two new Symfony UX CVEs and recommends upgrading to the patched versions 3.2.0 or 2.36.1 to mitigate XSS and path traversal vulnerabilities.

