CVE-2026-46634 (matched: php)

  • Saturday, 1st August, 2026
  • 16:05pm

Twig is a template tool for PHP websites that controls how your site's content and page layouts are displayed to visitors. A security flaw exists in Twig versions 3.9.0 through 3.26.0. If your site uses Twig's sandbox security feature (designed to block untrusted custom templates from running risky code), attackers could bypass that sandbox by using the built-in template_from_string and include functions to run unapproved template code on your site. This could lead to unintended content being shown to visitors or other security risks. This vulnerability is fully resolved in Twig version 3.26.0 and later releases.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-46634

« Back