CVE-2026-46634 (matched: php)

  • Thursday, 30th July, 2026
  • 16:04pm

Twig is a popular PHP template tool that many websites use to build and display page content. A security flaw has been identified in Twig versions 3.9.0 through 3.26.0. The issue affects the template_from_string() function, which is used to process small embedded templates. When this function is used alongside the include feature in a sandboxed template (a security guard designed to stop untrusted embedded code from running dangerous actions), the embedded template can bypass those safety checks and run without the intended security restrictions in place. This vulnerability is fully resolved in Twig version 3.26.0.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-46634

« Back