Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-46638— Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)

AI Predicted 7.5 Difficulty: Easy EPSS 0.27% · P18

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProductVersion RangeStatus
twigphpTwig< 3.26.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-46638

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
Source: CVE Program / CVE List V5
Vulnerability Description
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, and functions that should have been denied by SecurityPolicy::checkSecurity(). This issue is fixed in version 3.26.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
保护机制失效
Source: CVE Program / CVE List V5
Vulnerability Title
twigphp Twig 处理逻辑错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
twigphp Twig是twigphp的PHP模板引擎。 twigphp Twig 3.26.0之前版本存在处理逻辑错误漏洞,该漏洞源于在沙盒模式下,{% include %}可以包含之前已在沙盒外加载的模板,而无需重新调用checkSecurity(),导致缓存的模板可以使用本应被SecurityPolicy::checkSecurity()拒绝的标签、过滤器和函数。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
twigphpTwig < 3.26.0 -

II. Public POCs for CVE-2026-46638

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46638

登录查看更多情报信息。

Patches & Fixes for CVE-2026-46638 (1)

Vendor Advisories for CVE-2026-46638 (1)

Vendor Pages for CVE-2026-46638 (1)

Same Patch Batch · twigphp · 2026-07-14 · 17 CVEs total

CVE-2026-466347.7 HIGHTwig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized templ
CVE-2026-47730Twig: XSS in profiler HtmlDumper via unescaped template and profile names
CVE-2026-47732Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
CVE-2026-48806Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
CVE-2026-48805Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
CVE-2026-48808Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterfa
CVE-2026-48807Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filte
CVE-2026-49981Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes betwee
CVE-2026-46635Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
CVE-2026-46628Twig: The `spaceless` filter implicitly marks its output as safe
CVE-2026-46640Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
CVE-2026-46637Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
CVE-2026-46639Twig: Sandbox property and method bypass via object-destructuring assignment
CVE-2026-46627Twig: Sandbox resource exhaustion via unbounded `for` / `range()`
CVE-2026-46633Twig: PHP code injection via `{% use %}` template name
CVE-2026-46629Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled argu

IV. Related Vulnerabilities

V. Comments for CVE-2026-46638

No comments yet


Leave a comment