
Two Symfony UX CVEs, patch now. → CVE-2026-55877: ux_icon() renders unsanitized SVG → XSS → CVE-2026-55878: path traversal in Toolkit installer Upgrade to UX 3.2.0 or 2.36.1.
Post summary
Two new Symfony UX CVEs—CVE‑2026‑55877, an XSS via unsanitized SVG, and CVE‑2026‑55878, a path traversal in the Toolkit installer—have been disclosed. Users are urged to apply the patch by upgrading to UX 3.2.0 or 2.36.1.

