CVE-2025-11570
Description
Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data.
**Note:**
This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and Pattern Lab.
The package drupal-pattern-lab/unified-twig-extensions is unmaintained, the fix for this issue exists in version 1.1.1 of [drupal/unified_twig_ext](https://www.drupal.org/project/unified_twig_ext)
CWE
- CWE-79 — Cross-site Scripting (XSS)
Affected
- n/a / drupal-pattern-lab/unified-twig-extensions — v=0.0.0 <* [affected]
CVSS
- 4.0 score=4.8 severity=MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:P - 3.1 score=4.6 severity=MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:P
References
- https://security.snyk.io/vuln/SNYK-PHP-DRUPALPATTERNLABUNIFIEDTWIGEXTENSIONS-8400877
- https://github.com/drupal-pattern-lab/unified-twig-extensions/blob/862b9deccab544ca68e3aaaccc257d14acc9b1f6/example/_twig-components/functions/link.function.php%23L9
- https://www.drupal.org/sa-contrib-2023-041
Source
cvelistV5-main/cves/2025/11xxx/CVE-2025-11570.json