SCA: security update for easycorp/easyadmin-bundle (GHSA-8559-gwj3-q37r)

high Tenable Self-Hosted Container Security Plugin ID 444711

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13,
FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig
links to stored files for inline same-origin rendering without a download attribute or Content-Disposition
attachment header. When uploads are stored under the public web root, an attacker with access to an
affected form can upload HTML through FileField or SVG through ImageField, and JavaScript executes in an
authenticated administrator's origin when the file is opened from the backend. Exploitation requires a
privilege gap between the uploader and viewer. The issue can expose session or CSRF tokens and enable
privilege escalation, but does not permit PHP or PHTML code execution because Symfony guessExtension does
not produce those stored extensions. This issue is fixed in version 5.0.13. (CVE-2026-54087)

Solution

Update the easycorp/easyadmin-bundle library and its related packages to version 5.0.13 or later.

See Also

https://github.com/advisories/GHSA-8559-gwj3-q37r

Plugin Details

Severity: High

ID: 444711

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 7/15/2026

Updated: 9/15/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.81

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:P/A:N

CVSS Score Source: CVE-2026-54087

CVSS v3

Risk Factor: High

Base Score: 7.6

Temporal Score: 6.6

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/14/2026

Vulnerability Publication Date: 7/14/2026

Reference Information

CVE: CVE-2026-54087