CVE-2026-24425 (matched: php)

  • Saturday, 25th July, 2026
  • 10:04am

A security vulnerability has been found in Twig, a common tool used to build and render dynamic website templates. The flaw affects Twig versions 2.16.x, as well as all releases from 3.9.0 up to 3.25.x.

The issue lets attackers bypass Twig’s built-in template sandbox, a security feature meant to restrict what code templates are allowed to run. This bypass only works if the sandbox is enabled through a source policy rather than being turned on for all templates on a site. If an attacker has the ability to submit or edit templates on your website, they can exploit this weakness to run unauthorized code on your hosting environment.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-24425

« Back