目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-48805— twigphp Twig 处理逻辑错误漏洞

AI Predicted 6.5 Difficulty: Easy EPSS 0.27% · P19

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
twigphpTwig< 3.27.0affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-48805の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
ソース: CVE Program / CVE List V5
脆弱性説明
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(), twig_array_every(), and twig_check_arrow_in_sandbox() to bypass sandbox callable restrictions. This issue is fixed in version 3.27.0.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
保护机制失效
ソース: CVE Program / CVE List V5
脆弱性タイトル
twigphp Twig 处理逻辑错误漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
twigphp Twig是twigphp的PHP模板引擎。 twigphp Twig 3.27.0之前版本存在处理逻辑错误漏洞,该漏洞源于src/Resources/core.php中的内部封装未传递当前沙箱状态,允许旧式调用绕过沙箱可调用项限制。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
twigphpTwig < 3.27.0 -

II. CVE-2026-48805の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-48805のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-48805 补丁与修复 (1)

CVE-2026-48805 厂商安全公告 (1)

CVE-2026-48805 厂商页面 (1)

Same Patch Batch · twigphp · 2026-07-14 · 17 CVEs total

CVE-2026-466347.7 HIGHTwig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized templ
CVE-2026-47730Twig: XSS in profiler HtmlDumper via unescaped template and profile names
CVE-2026-47732Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
CVE-2026-48806Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
CVE-2026-48808Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterfa
CVE-2026-48807Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filte
CVE-2026-49981Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes betwee
CVE-2026-46635Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
CVE-2026-46638Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete f
CVE-2026-46628Twig: The `spaceless` filter implicitly marks its output as safe
CVE-2026-46640Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
CVE-2026-46637Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
CVE-2026-46639Twig: Sandbox property and method bypass via object-destructuring assignment
CVE-2026-46627Twig: Sandbox resource exhaustion via unbounded `for` / `range()`
CVE-2026-46633Twig: PHP code injection via `{% use %}` template name
CVE-2026-46629Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled argu

IV. 関連脆弱性

V. CVE-2026-48805へのコメント

まだコメントはありません


コメントを残す