VYPR
Medium severity5.4OSV Advisory· Published Jul 14, 2026· Updated Jul 16, 2026

CVE-2026-46637

CVE-2026-46637

Description

Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
twig/markdown-extraPackagist
< 3.26.03.26.0
twig/cssinliner-extraPackagist
< 3.26.03.26.0

Affected products

2
  • Twigphp/TwigOSV2 versions
    v3.25.0, v3.24.0, v3.23.0, …+ 1 more
    • (no CPE)range: v3.25.0, v3.24.0, v3.23.0, …
    • (no CPE)range: <3.26.0

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.