Description
EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline same-origin rendering without a download attribute or Content-Disposition attachment header. When uploads are stored under the public web root, an attacker with access to an affected form can upload HTML through FileField or SVG through ImageField, and JavaScript executes in an authenticated administrator's origin when the file is opened from the backend. Exploitation requires a privilege gap between the uploader and viewer. The issue can expose session or CSRF tokens and enable privilege escalation, but does not permit PHP or PHTML code execution because Symfony guessExtension does not produce those stored extensions. This issue is fixed in version 5.0.13.
Published: 2026-09-14
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting that can steal credentials and elevate privileges
Action: Immediate Patch
AI Analysis

Impact

EasyAdminBundle from version 5.0.0 up to 5.0.13 allows FileField and ImageField to accept browser‑executable uploads. The default template at templates/crud/field/file.html.twig links to stored files for inline same‑origin rendering without a download attribute or Content‑Disposition header. When uploads are placed under the public web root, an attacker with access to an affected form can upload HTML via FileField or SVG via ImageField, and JavaScript runs in an authenticated administrator’s browser context when the file is opened from the backend. This stored XSS can expose session or CSRF tokens and facilitate privilege escalation. The flaw is limited to browser‑executable uploads and does not allow execution of server‑side PHP or PHTML code because Symfony’s extension filtering prevents those types.

Affected Systems

The affected product is EasyAdminBundle from EasyCorp, with insecure inline rendering in FileField and ImageField templates in versions 5.0.0 to 5.0.13. This impacts Symfony applications that use the default templates and host uploaded files in the public web root.

Risk and Exploitability

The CVSS score of 7.6 indicates a high‑severity risk. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a moderate privilege gap: the attacker must have the ability to submit files to the vulnerable form and a separate authenticated administrator must later view the file. Once satisfied, the attacker can then execute malicious JavaScript in the administrator’s context, potentially facilitating further attacks. While the likelihood of exploitation is not quantified, the high CVSS and nature of the flaw imply that it is a significant concern for applications exposed to untrusted file uploads.

Generated by OpenCVE AI on September 20, 2026 at 23:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade EasyAdminBundle to version 5.0.13 or later to remove the insecure inline rendering
  • Validate uploaded files and reject dangerous extensions such as .html, .svg, and other executable types
  • Configure the application to serve uploads with a Content‑Disposition: attachment header or through a dedicated download route instead of inline rendering

Generated by OpenCVE AI on September 20, 2026 at 23:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8559-gwj3-q37r EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline same-origin rendering without a download attribute or Content-Disposition attachment header. When uploads are stored under the public web root, an attacker with access to an affected form can upload HTML through FileField or SVG through ImageField, and JavaScript executes in an authenticated administrator's origin when the file is opened from the backend. Exploitation requires a privilege gap between the uploader and viewer. The issue can expose session or CSRF tokens and enable privilege escalation, but does not permit PHP or PHTML code execution because Symfony guessExtension does not produce those stored extensions. This issue is fixed in version 5.0.13.
Title EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
Weaknesses CWE-434
CWE-79
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:00:23.879Z

Reserved: 2026-06-11T18:44:47.761Z

Link: CVE-2026-54087

cve-icon Vulnrichment

Updated: 2026-09-14T19:00:16.120Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:51.930

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-54087

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:15:04Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')