easycorp/easyadmin-bundle Security Advisories for v4.24.8 (2)
-
[HIGH] Custom action dispatcher bypasses access_control on other routes
PKSA-7ck7-y4vp-mmcz CVE-2026-81892 GHSA-g2fm-8hr4-j82h
Affected version: >=4.0.0,<4.29.16|>=5.0.0,<5.5.1
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Path traversal and reflected XSS in Flag and Icon Twig components
PKSA-z6tn-c4hk-yb9y GHSA-2wwr-9x6f-88gp
Affected version: >=4.0.0,<4.29.10|>=5.0.0,<5.0.10
Reported by:
FriendsOfPHP/security-advisories, GitHub