CVE-2026-55878Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-20); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-20: 1Mentions · 2026-06-24: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-20: 1Technical Details · 2026-06-24: 106-2006-24
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-06-201
Disclosure1
2026-06-241
Patch1
Full discourse2 posts
  • Diego Artiles@dartilesm
    Patch

    Two Symfony UX CVEs, patch now. → CVE-2026-55877: ux_icon() renders unsanitized SVG → XSS → CVE-2026-55878: path traversal in Toolkit installer Upgrade to UX 3.2.0 or 2.36.1.

    Post summary

    Two new Symfony UX CVEs—CVE‑2026‑55877, an XSS via unsanitized SVG, and CVE‑2026‑55878, a path traversal in the Toolkit installer—have been disclosed. Users are urged to apply the patch by upgrading to UX 3.2.0 or 2.36.1.

    0000041
    49 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Symfony, Path Traversal, #CVE-2026-55878 (Critical) -DC-Jun2026-527 https://dailycve.com/symfony-path-traversal-cve-2026-55878-critical-dc-jun2026-527/

    Post summary

    DailyCVE announces the discovery of a critical path‑traversal vulnerability in Symfony (CVE‑2026‑55878) without providing a PoC, exploit, or patch information.

    0000033
    215 followersView on X

Explore more