CVE-2026-24425 (matched: php)

  • Sunday, 26th July, 2026
  • 10:05am

A security flaw has been identified in Twig, a widely used tool for building dynamic PHP websites. The vulnerability impacts Twig versions 2.16.x and 3.9.0 through 3.25.x.

When a site uses Twig's sandbox security feature enabled via a source policy (rather than turned on globally for all templates), attackers who have the ability to edit or upload site templates can bypass these security restrictions. They can exploit this gap to run arbitrary, unauthorized code on your website.

Running unapproved code on your site could allow attackers to take unwanted actions using your hosting account and website resources.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-24425

« Back