CVE-2025-24374

MEDIUM4.3EPSS 0.30%

Twig security issue where escaping was missing when using null coalesce operator

Published: 1/29/2025Modified: 5/27/2026
Also known as:GHSA-3xg3-cgvq-2xwrDEBIAN-CVE-2025-24374

Description

Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

References (7)