symfony/html-sanitizer is vulnerable to User Interface (UI) Misrepresentation of Critical Information
61
Medium Risk
UrlSanitizer allows explicit-direction Unicode BiDi formatting characters in sanitized URL attributes. Those characters can change the visual order of link text or URLs in rendered HTML. Pre-fix sanitized content can display a destination differently from the real link target, enabling phishing-style spoofing. The fix rejects URLs containing those BiDi control characters.
You are affected if you are using a version that falls within the vulnerable range.
symfony/html-sanitizer is vulnerable to User Interface (UI) Misrepresentation of Critical Information in versions 6.1.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.
Upgrade the symfony/html-sanitizer and/or symfony/symfony library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant