Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.
Metrics
Affected Vendors & Products
References
History
Mon, 27 Jul 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Twig
Twig cssinliner-extra Twig markdown-extra Twigphp Twigphp twig |
|
| Vendors & Products |
Twig
Twig cssinliner-extra Twig markdown-extra Twigphp Twigphp twig |
Thu, 16 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0. | |
| Title | Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']` | |
| Weaknesses | CWE-116 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-07-14T21:25:20.141Z
Updated: 2026-07-16T15:05:57.087Z
Reserved: 2026-05-15T20:11:54.584Z
Link: CVE-2026-46637
Updated: 2026-07-16T15:05:52.849Z
No data.
No data.