CVE-2026-46637

MEDIUM

Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`

Title source: cna
STIX 2.1

Description

Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.

Scores

CVSS v3 5.4
EPSS 0.0018
EPSS Percentile 7.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-116 CWE-79
Status published
Products (4)
symfony/twig < 3.26.0
twig/cssinliner-extra < 3.26.0
twig/markdown-extra < 3.26.0
twigphp/Twig < 3.26.0
Published Jul 14, 2026
Tracked Since Jul 15, 2026