PT-2025-41502 · Unknown · Drupal-Pattern-Lab/Unified-Twig-Extensions+2

·

CVE-2025-11570

·

Published

2025-10-10

·

Updated

2026-05-22

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions drupal-pattern-lab/unified-twig-extensions versions 0.0.0 through 1.1.0
Description The package contains a Cross-site Scripting (XSS) issue because of inadequate data filtering. This is only exploitable when the code runs outside of Drupal, as the function is designed for use in both Drupal and Pattern Lab.
Recommendations Update to version 1.1.1 or later of drupal/unified twig ext.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11570
GHSA-64MV-9655-37HX

Affected Products

Pattern Lab
Drupal-Pattern-Lab/Unified-Twig-Extensions
Drupal/Unified Twig Ext