Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-46639— Twig: Sandbox property and method bypass via object-destructuring assignment

AI Predicted 8.1 Difficulty: Easy EPSS 0.35% · P28

Possible ATT&CK Techniques 1AI

T1210 · Exploitation of Remote Services

Affected Version Matrix 1

VendorProductVersion RangeStatus
twigphpTwig>= 3.24.0, < 3.26.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-46639

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Twig: Sandbox property and method bypass via object-destructuring assignment
Source: CVE Program / CVE List V5
Vulnerability Description
Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template to read public properties or invoke public getters on objects passed to the template engine. This issue is fixed in version 3.26.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
保护机制失效
Source: CVE Program / CVE List V5
Vulnerability Title
twigphp Twig 处理逻辑错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
twigphp Twig是twigphp的PHP模板引擎。 twigphp Twig 3.24.0版本至3.26.0之前版本存在处理逻辑错误漏洞,该漏洞源于对象解构赋值将sandbox参数硬编码为false,导致属性和方法策略检查被禁用,使得具有写入权限的攻击者能够读取传递给模板引擎的对象的公共属性或调用公共getter方法。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
twigphpTwig >= 3.24.0, < 3.26.0 -

II. Public POCs for CVE-2026-46639

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46639

登录查看更多情报信息。

Vendor Advisories for CVE-2026-46639 (1)

Vendor Pages for CVE-2026-46639 (1)

Same Patch Batch · twigphp · 2026-07-14 · 17 CVEs total

CVE-2026-466347.7 HIGHTwig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized templ
CVE-2026-47730Twig: XSS in profiler HtmlDumper via unescaped template and profile names
CVE-2026-47732Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
CVE-2026-48806Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
CVE-2026-48805Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
CVE-2026-48808Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterfa
CVE-2026-48807Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filte
CVE-2026-49981Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes betwee
CVE-2026-46635Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
CVE-2026-46638Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete f
CVE-2026-46628Twig: The `spaceless` filter implicitly marks its output as safe
CVE-2026-46640Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
CVE-2026-46637Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
CVE-2026-46627Twig: Sandbox resource exhaustion via unbounded `for` / `range()`
CVE-2026-46633Twig: PHP code injection via `{% use %}` template name
CVE-2026-46629Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled argu

IV. Related Vulnerabilities

V. Comments for CVE-2026-46639

No comments yet


Leave a comment