A security flaw has been found in Twig, a popular tool many websites use to build and render dynamic page templates. The vulnerability impacts Twig versions 2.16.x, as well as all 3.x releases from 3.9.0 through 3.25.x.
This issue is a sandbox bypass. Twig includes a sandbox feature designed to lock down what template code can do to block unauthorized changes to your site. If your site uses this sandbox feature set up via a source policy, and an attacker has the ability to edit or upload templates to your site, they could exploit this flaw to run arbitrary code on your hosting account. This could let them make unauthorized changes to your site, access sensitive information, or take other unapproved actions.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-24425