216.73.216.226

CVE-2026-24425

· Published 20/05/2026 14:16 · Modified 20/05/2026 14:25

Labels: CVE-2026-24425 2026-05-20CVE-2026-24425CWE-693[email protected]

Essential information

Published
20/05/2026 14:16
Modified
20/05/2026 14:25
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sensiolabs / twig cpe:2.3:a:sensiolabs:twig:2.16:*:*:*:*:*:*:*
sensiolabs / twig cpe:2.3:a:sensiolabs:twig:3.9.0-3.25:*:*:*:*:*:*:*

References