CVE-2023-41336: Symfony Ux Autocomplete

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could successfully submit an entity id for an `EntityType` that is *not* part of the valid choices. The problem has been fixed in `symfony/ux-autocomplete` version 2.11.2.

Affected products

  • Symfony Ux Autocomplete: before 2.11.2 (fixed in 2.11.2)

Published 2023-09-11. Last modified 2026-06-17.