CVE-2026-46634 (matched: php)

  • Saturday, 1st August, 2026
  • 04:05am

Twig is a common tool used to build dynamic PHP websites, handling how page content is formatted and displayed. A security flaw has been identified in Twig versions 3.9.0 up to 3.25.0. The bug impacts Twig's sandbox security feature, which is designed to block untrusted template code from running restricted, potentially harmful actions. For sites that use Twig's template_from_string and include functions, a maliciously crafted template could bypass this sandbox protection to run code that the security feature was supposed to block. This issue is resolved in Twig version 3.26.0.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-46634

« Back