PT-2025-41502 · Unknown · Pattern Lab+2

Pierre Rudloff

·

Published

2025-10-10

·

Updated

2025-10-13

·

CVE-2025-11570

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions drupal-pattern-lab/unified-twig-extensions versions 0.0.0 through 1.1.0
Description The package contains a Cross-site Scripting (XSS) issue because of inadequate data filtering. This is only exploitable when the code runs outside of Drupal, as the function is designed for use in both Drupal and Pattern Lab.
Recommendations Update to version 1.1.1 or later of drupal/unified twig ext.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-11570
GHSA-64MV-9655-37HX

Affected Products

Pattern Lab
Drupal-Pattern-Lab/Unified-Twig-Extensions
Drupal/Unified Twig Ext