symfony/twig-bridge
Provides integration for Twig with various Symfony components
Activity
- Latest release
- Jul 23, 2026
- Total releases
- 557
- Cadence
- ~daily
- Last 12 months
- 44
Reach
- Stars
- 2.5k
Details
- License
- MIT
- First release
- Sep 29, 2011
| Version | Released | |
|---|---|---|
v8.1.2
patch
|
v8.1.2
patch
Dependencies (2)
Changelog
Compare changes
|
|
v8.0.15
patch
| ||
v7.4.15
patch
| ||
v6.4.43
patch
|
v6.4.43
patch
Dependencies (3)
Changelog
Compare changes
|
|
v8.1.1
patch
| ||
v8.0.14
patch
| ||
v7.4.14
patch
| ||
v6.4.42
patch
| ||
v8.1.0
minor
| ||
v8.1.0-BETA3
pre
| ||
v6.4.40
patch
| ||
v8.1.0-BETA1
pre
| ||
v8.0.12
patch
| ||
v7.4.12
patch
| ||
v7.4.8
patch
| ||
v8.0.8
patch
| ||
v6.4.36
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v6.4.24
v6.4.25
v6.4.30
v6.4.31
v6.4.32
v6.4.34
v6.4.35
v6.4.36
Fixed in
6.4.40
References
Updated May 27, 2026 · Source: OSV.dev | ||
v8.0.7
patch
| ||
v7.4.7
patch
| ||
v6.4.35
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v6.4.24
v6.4.25
v6.4.30
v6.4.31
v6.4.32
v6.4.34
v6.4.35
v6.4.36
Fixed in
6.4.40
References
Updated May 27, 2026 · Source: OSV.dev | ||
v8.0.6
patch
| ||
v7.4.6
patch
| ||
v6.4.34
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v6.4.24
v6.4.25
v6.4.30
v6.4.31
v6.4.32
v6.4.34
v6.4.35
v6.4.36
Fixed in
6.4.40
References
Updated May 27, 2026 · Source: OSV.dev | ||
v8.0.5
patch
| ||
v7.4.5
patch
| ||
v7.3.11
patch
| ||
v8.0.4
patch
| ||
v7.4.4
patch
| ||
v7.3.10
patch
| ||
v6.4.32
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v6.4.24
v6.4.25
v6.4.30
v6.4.31
v6.4.32
v6.4.34
v6.4.35
v6.4.36
Fixed in
6.4.40
References
Updated May 27, 2026 · Source: OSV.dev | ||
v8.0.3
patch
| ||
v7.4.3
patch
| ||
v7.3.9
patch
| ||
v6.4.31
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v6.4.24
v6.4.25
v6.4.30
v6.4.31
v6.4.32
v6.4.34
v6.4.35
v6.4.36
Fixed in
6.4.40
References
Updated May 27, 2026 · Source: OSV.dev | ||
v8.0.1
patch
| ||
v7.4.1
patch
| ||
v7.3.8
patch
| ||
v6.4.30
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v6.4.24
v6.4.25
v6.4.30
v6.4.31
v6.4.32
v6.4.34
v6.4.35
v6.4.36
Fixed in
6.4.40
References
Updated May 27, 2026 · Source: OSV.dev | ||
v8.0.0
major
| ||
v7.4.0
minor
| ||
v7.3.6
patch
| ||
v8.0.0-BETA2
pre
| ||
v7.4.0-BETA1
pre
| ||
v8.0.0-BETA1
pre
| ||
v7.3.3
patch
| ||
v6.4.25
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v6.4.24
v6.4.25
v6.4.30
v6.4.31
v6.4.32
v6.4.34
v6.4.35
v6.4.36
Fixed in
6.4.40
References
Updated May 27, 2026 · Source: OSV.dev | ||
v7.3.2
patch
| ||
v7.2.9
patch
|
v7.2.9
patch
Dependencies (3)
Changelog
Compare changes
|
|
v6.4.24
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v6.4.24
v6.4.25
v6.4.30
v6.4.31
v6.4.32
v6.4.34
v6.4.35
v6.4.36
Fixed in
6.4.40
References
Updated May 27, 2026 · Source: OSV.dev | ||
v7.3.0
minor
|
v7.3.0
minor
Changelog
Compare changes
|