PT-2026-45157 · Twig · Twig

Published

2026-05-21

·

Updated

2026-06-05

·

CVE-2026-47730

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Twig (affected versions not specified)
Description The TwigProfilerDumperHtmlDumper component fails to escape the output of Profile::getTemplate() and Profile::getName() when writing to HTML. If an attacker can control the template name—which may originate from an ArrayLoader array key or a database-backed loader row ID—they can inject arbitrary HTML. This results in the browser executing the injected markup when rendering the profiler dump. This is an output-encoding issue within the profiler and debug tooling.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-47730
GHSA-2G2G-8P8H-FGWM

Affected Products

Twig