{"id":"GHSA-64mv-9655-37hx","summary":"drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS","details":"Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data.\n\n**Note:**\nThis is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and Pattern Lab.\n\nThe package drupal-pattern-lab/unified-twig-extensions is unmaintained, the fix for this issue exists in version 1.1.1 of [drupal/unified_twig_ext](https://www.drupal.org/project/unified_twig_ext), but is not published to the Composer PHP registry.","aliases":["CVE-2025-11570"],"modified":"2025-10-11T00:12:31.431371Z","published":"2025-10-10T06:30:55Z","database_specific":{"nvd_published_at":"2025-10-10T05:15:33Z","cwe_ids":["CWE-79"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2025-10-10T23:51:44Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11570"},{"type":"PACKAGE","url":"https://github.com/drupal-pattern-lab/unified-twig-extensions"},{"type":"WEB","url":"https://github.com/drupal-pattern-lab/unified-twig-extensions/blob/862b9deccab544ca68e3aaaccc257d14acc9b1f6/example/_twig-components/functions/link.function.php%23L9"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-PHP-DRUPALPATTERNLABUNIFIEDTWIGEXTENSIONS-8400877"},{"type":"WEB","url":"https://www.drupal.org/project/unified_twig_ext"},{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2023-041"}],"affected":[{"package":{"name":"drupal-pattern-lab/unified-twig-extensions","ecosystem":"Packagist","purl":"pkg:composer/drupal-pattern-lab/unified-twig-extensions"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.1.0"}]}],"versions":["v0.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-64mv-9655-37hx/GHSA-64mv-9655-37hx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"}]}