Junglewise Threat Intelligence

CVE-2026-46637: Twig XSS in markdown-extra and cssinliner-extra filters

CVE-2026-46637 · Severity: medium · CVSS 4 · Published 2026-07-14

Technologies: Twig PHP Twig. Vendors: Twig PHP, Packagist.

Executive brief

Twig, a popular template engine for PHP, contains a vulnerability in its optional markdown and CSS inliner extensions. Certain filters incorrectly tell the system that their output is safe for all parts of a webpage, including sensitive areas like JavaScript or CSS blocks. This could allow an attacker to inject malicious scripts into a website, potentially leading to unauthorized actions or data theft from users.

Technical details

A vulnerability exists in Twig's markdown-extra and cssinliner-extra extensions where several filters (html_to_markdown, markdown_to_html, and inline_css) were registered with the 'is_safe => [all]' attribute. This incorrectly signals to Twig's auto-escaper that the output is safe for any context, including JavaScript, CSS, and URLs. Consequently, if attacker-controlled input is processed by these filters and then placed in a sensitive context, it remains unescaped. For example, the html_to_markdown filter could decode HTML entities into live tags, and markdown_to_html could allow HTML injection into script blocks. The issue is resolved in version 3.26.0 by correctly restricting the 'is_safe' scope to 'html' or removing it to allow context-aware auto-escaping.

Affected products

  • twigphp Twig < 3.26.0
  • twig markdown-extra < 3.26.0
  • twig cssinliner-extra < 3.26.0

Timeline

  • 2026-05-20: patched: Version 3.26.0 released
  • 2026-05-20: advisory: GitHub Security Advisory GHSA-jv8m-2544-3pg3 published
  • 2026-07-14: disclosed: CVE-2026-46637 published to NVD

References