This security notice is for websites that use Twig, a common template engine for PHP-based sites and web applications that build and display page content. Certain Twig versions (2.16.x and 3.9.0 through 3.25.x) have a sandbox bypass vulnerability. Twig's sandbox is a built-in safety feature meant to block untrusted code from running when users are allowed to edit or submit template content for your site. This flaw only affects sites that have the sandbox turned on via a source policy, rather than the default global setting. Attackers who can submit or edit templates on an affected site can exploit this flaw to get around the sandbox's safety checks. This may let them run their own unwanted code on your site, which could lead to unauthorized changes to your site, stolen data, or other security problems.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-24425