drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS
Low severity
GitHub Reviewed
Published
Oct 10, 2025
to the GitHub Advisory Database
•
Updated Oct 10, 2025
Package
Affected versions
<= 0.1.0
Patched versions
None
Description
Published by the National Vulnerability Database
Oct 10, 2025
Published to the GitHub Advisory Database
Oct 10, 2025
Reviewed
Oct 10, 2025
Last updated
Oct 10, 2025
Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data.
Note:
This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and Pattern Lab.
The package drupal-pattern-lab/unified-twig-extensions is unmaintained, the fix for this issue exists in version 1.1.1 of drupal/unified_twig_ext, but is not published to the Composer PHP registry.
References