GHSA-2g2g-8p8h-fgwm
Twig: XSS in profiler HtmlDumper via unescaped template and profile names
Quick fix
GHSA-2g2g-8p8h-fgwm — twig/twig: upgrade to the fixed version with the command below.
composer require twig/twig:^3.26.0Details
### Description
`Twig\Profiler\Dumper\HtmlDumper` writes `Profile::getTemplate()` and `Profile::getName()` straight into its HTML output without escaping:
```php protected function formatTemplate(Profile $profile, $prefix): string { return \sprintf('%s└ <span style="background-color: %s">%s</span>', $prefix, self::$colors['template'], $profile->getTemplate()); } ```
The template name comes from the loader (the array key for `ArrayLoader`, a row id for a database-backed loader, etc.). When that name is attacker-controlled, the profiler dump emits arbitrary HTML, and any browser that renders it executes the injected markup. This is an output-encoding bug in profiler/debug tooling, not a sandbox escape.
### Resolution
`HtmlDumper` now runs both `Profile::getTemplate()` and `Profile::getName()` through `htmlspecialchars()` before inserting them into the HTML output.
### Credits
Twig would like to thank El Kharoubi Iosif for reporting the issue and Nicolas Grekas for fixing it.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/twigphp/Twig/security/advisories/GHSA-2g2g-8p8h-fgwm[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-47730.yaml[WEB]
- https://github.com/twigphp/Twig[PACKAGE]
- https://github.com/twigphp/Twig/releases/tag/v3.26.0[WEB]
- https://symfony.com/cve-2026-47730[WEB]