An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSensiolabs Symfony
APPSensiolabs4.2.0 – 4.2.12 (excl.)4.3.0 – 4.3.8 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References
Related vulnerabilities
CVE-2026-45063CRITICAL9.1PL ✓same product
Symfony X509Authenticator — obejście uwierzytelniania przez błędny regex DN
CVE-2019-18889CRITICAL9.8PL ✓same product
Symfony: zdalne wykonanie kodu przez serializację adaptera cache
CVE-2017-11365CRITICAL9.8PL ✓same product
Nieprawidłowa kontrola dostępu w komponencie Password validator — Symfony
CVE-2019-10910CRITICAL9.8PL ✓same product
SQL Injection i RCE w Symfony przez niezwalidowane identyfikatory serwisów
CVE-2019-10913CRITICAL9.8PL ✓same product
Symfony: SQL injection i XSS przez niezwalidowane metody HTTP