Spotted by Psalm taint analysis. In \Tuleap_Template is called on possibly untrusted data. This should be avoided to not give malicious users a way to influence the execution context.
Note there is no security impact, as the existing code does not pass untrusted information.