Medium severity5.4OSV Advisory· Published Jul 14, 2026· Updated Jul 21, 2026
CVE-2026-47730
CVE-2026-47730
Description
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
twig/twigPackagist | >= 3.0.0, < 3.26.0 | 3.26.0 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/twigphp/Twig/commit/a5f6e8793e603ef34fa86aed2a72f9fbe0b43745nvdPatch
- github.com/advisories/GHSA-2g2g-8p8h-fgwmghsaADVISORY
- github.com/twigphp/Twig/security/advisories/GHSA-2g2g-8p8h-fgwmnvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-47730.yamlghsaWEB
- github.com/twigphp/Twig/releases/tag/v3.26.0nvdRelease NotesWEB
- symfony.com/cve-2026-47730ghsaWEB
News mentions
0No linked articles in our index yet.