{"id":"GHSA-3xg3-cgvq-2xwr","summary":"Twig security issue where escaping was missing when using null coalesce operator","details":"When using the `??` operator, output escaping was missing for the expression on the left side of the operator.\n","aliases":["CVE-2025-24374"],"modified":"2025-01-30T15:39:37.595767Z","published":"2025-01-29T18:41:43Z","database_specific":{"github_reviewed_at":"2025-01-29T18:41:43Z","nvd_published_at":"2025-01-29T16:15:44Z","cwe_ids":["CWE-74"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/twigphp/Twig/security/advisories/GHSA-3xg3-cgvq-2xwr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24374"},{"type":"WEB","url":"https://github.com/twigphp/Twig/commit/38576b12f05df3cc871bf68f39ccb46b418334a3"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2025-24374.yaml"},{"type":"PACKAGE","url":"https://github.com/twigphp/Twig"},{"type":"WEB","url":"https://symfony.com/blog/twig-cve-2025-24374-missing-output-escaping-for-the-null-coalesce-operator"}],"affected":[{"package":{"name":"twig/twig","ecosystem":"Packagist","purl":"pkg:composer/twig/twig"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.16.0"},{"fixed":"3.19.0"}]}],"versions":["v3.16.0","v3.17.0","v3.17.1","v3.18.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-3xg3-cgvq-2xwr/GHSA-3xg3-cgvq-2xwr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}