GHSA-q847-2q57-wmr3

    Dashboard / Vulnerabilities / GHSA-q847-2q57-wmr3

    GHSA-q847-2q57-wmr3

    Published: 12 Nov 2023Last Modified: 10 Sept 2026

    Summary: Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters

    Details: ### Description Some Twig filters in CodeExtension use "is_safe=html" but don't actually ensure their input is safe. ### Resolution Symfony now escapes the output of the affected filters. The patch for this issue is available [here](https://github.com/symfony/symfony/commit/9da9a145ce57e4585031ad4bee37c497353eec7c) for branch 4.4. ### Credits We would like to thank Pierre Rudloff for reporting the issue and to Nicolas Grekas for providing the fix.

    Affected packages

    Package

    Name: symfony/twig-bridge

    Purl: pkg:composer/symfony/twig-bridge

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 2.0.0
    Fixed -4.4.51

    Affected versions

    2.0.4
    2.0.5
    2.0.6
    2.0.7

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-q847-2q57-wmr3 | CVE-DB