{"id":"GHSA-2g2g-8p8h-fgwm","summary":"Twig: XSS in profiler HtmlDumper via unescaped template and profile names","details":"### Description\n\n`Twig\\Profiler\\Dumper\\HtmlDumper` writes `Profile::getTemplate()` and `Profile::getName()` straight into its HTML output without escaping:\n\n```php\nprotected function formatTemplate(Profile $profile, $prefix): string\n{\n    return \\sprintf('%s└ \u003cspan style=\"background-color: %s\"\u003e%s\u003c/span\u003e', $prefix, self::$colors['template'], $profile-\u003egetTemplate());\n}\n```\n\nThe template name comes from the loader (the array key for `ArrayLoader`, a row id for a database-backed loader, etc.). When that name is attacker-controlled, the profiler dump emits arbitrary HTML, and any browser that renders it executes the injected markup. This is an output-encoding bug in profiler/debug tooling, not a sandbox escape.\n\n### Resolution\n\n`HtmlDumper` now runs both `Profile::getTemplate()` and `Profile::getName()` through `htmlspecialchars()` before inserting them into the HTML output.\n\n### Credits\n\nTwig would like to thank El Kharoubi Iosif for reporting the issue and Nicolas Grekas for fixing it.","aliases":["CVE-2026-47730"],"modified":"2026-09-10T03:51:07.469938305Z","published":"2026-06-05T21:46:26Z","database_specific":{"github_reviewed_at":"2026-06-05T21:46:26Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/twigphp/Twig/security/advisories/GHSA-2g2g-8p8h-fgwm"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-47730.yaml"},{"type":"PACKAGE","url":"https://github.com/twigphp/Twig"},{"type":"WEB","url":"https://github.com/twigphp/Twig/releases/tag/v3.26.0"},{"type":"WEB","url":"https://symfony.com/cve-2026-47730"}],"affected":[{"package":{"name":"twig/twig","ecosystem":"Packagist","purl":"pkg:composer/twig/twig"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.26.0"}]}],"versions":["v3.0.0","v3.0.1","v3.0.2","v3.0.3","v3.0.4","v3.0.5","v3.1.0","v3.1.1","v3.10.0","v3.10.1","v3.10.2","v3.10.3","v3.11.0","v3.11.1","v3.11.2","v3.11.3","v3.12.0","v3.13.0","v3.14.0","v3.14.1","v3.14.2","v3.15.0","v3.16.0","v3.17.0","v3.17.1","v3.18.0","v3.19.0","v3.2.1","v3.20.0","v3.21.0","v3.21.1","v3.22.0","v3.22.1","v3.22.2","v3.23.0","v3.24.0","v3.25.0","v3.3.0","v3.3.1","v3.3.10","v3.3.2","v3.3.3","v3.3.4","v3.3.5","v3.3.6","v3.3.7","v3.3.8","v3.3.9","v3.4.0","v3.4.1","v3.4.2","v3.4.3","v3.5.0","v3.5.1","v3.6.0","v3.6.1","v3.7.0","v3.7.1","v3.8.0","v3.9.0","v3.9.1","v3.9.2","v3.9.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-2g2g-8p8h-fgwm/GHSA-2g2g-8p8h-fgwm.json"}}],"schema_version":"1.9.0"}