VYPR
Medium severity5.4OSV Advisory· Published Jul 14, 2026· Updated Jul 21, 2026

CVE-2026-47730

CVE-2026-47730

Description

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
twig/twigPackagist
>= 3.0.0, < 3.26.03.26.0

Affected products

2
  • Twigphp/TwigOSV2 versions
    v3.25.0, v3.24.0, v3.23.0, …+ 1 more
    • (no CPE)range: v3.25.0, v3.24.0, v3.23.0, …
    • (no CPE)range: 3.0.0 - 3.25.9

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.