CVE-2025-24374
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: security-advisories@github.com (Secondary)
Description
Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
References (2)
Source: security-advisories@github.com
Source: security-advisories@github.com
Timeline
No history available yet.