Change record status: 
Project: 
Introduced in branch: 
9.4.x
Introduced in version: 
9.4.0
Description: 

Incorrect usage of the token system can lead to double-escaping or corruption. To guard against this, the token API has been enhanced with improved comments and a new method to handle token replacement of plain text. The correct usage is as follows:

  • replace() The input is markup and return value are markup. Note that the return value must be treated as unsafe even if the input was safe markup. This is necessary because an attacker could craft an input string and token value that, although each safe individually, would be unsafe when combined by token replacement.
  • replacePlain() The input and return value are plain text.

Before

use Drupal\Component\Render\PlainTextOutput;
use Drupal\Component\Utility\Html;

PlainTextOutput::renderFromHtml($token_service->replace(Html::escape($plain)));

After

$token_service->replacePlain($plain);
Impacts: 
Module developers