CVE-2026-46637
בינונית 5.4
תיאור (מקור, אנגלית)
Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.
מדדים
- CVSS 3.1
-
5.4 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N - CVSS 4.0
-
5.1 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-8/8/2026
- CWE
- CWE-116, CWE-79
מוצרים מושפעים
symfony: twig
קישורים
- https://github.com/twigphp/Twig/security/advisories/GHSA-jv8m-2544-3pg3 Vendor Advisory
- https://github.com/twigphp/Twig/commit/84982072c79a7417b0d158a401d91344f3658299 Patch
- https://github.com/twigphp/Twig/commit/e36489d3521ecbfc08bdcc61294302557035f14a Patch
- https://github.com/twigphp/Twig/releases/tag/v3.26.0 Release Notes