PT-2026-47207 · Twig · Twig

CVE-2026-46636

·

Published

2026-05-27

·

Updated

2026-09-04

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Twig (PHP templating engine) (affected versions not specified)
Description An allow-list bypass exists within the Sandbox filter, tag, and function mechanisms, which could allow an attacker to execute unauthorized actions by circumventing the security restrictions intended to isolate the execution environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46636
GHSA-64JR-QJX4-W2FH

Affected Products

Twig