Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49981— Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`

AI Predicted 7.5 Difficulty: Moderate EPSS 0.21% · P12

Possible ATT&CK Techniques 1AI

T1055 · Process Injection

Affected Version Matrix 1

VendorProductVersion RangeStatus
twigphpTwig< 3.27.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-49981

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
Source: CVE Program / CVE List V5
Vulnerability Description
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
保护机制失效
Source: CVE Program / CVE List V5
Vulnerability Title
twigphp Twig 处理逻辑错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
twigphp Twig是twigphp的PHP模板引擎。 twigphp Twig 3.27.0之前版本存在安全漏洞,该漏洞源于沙箱状态变化后过滤、标签和函数允许列表判断缓存未更新,允许后续沙箱渲染复用不同策略检查的模板,可能导致权限绕过。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
twigphpTwig < 3.27.0 -

II. Public POCs for CVE-2026-49981

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-49981

登录查看更多情报信息。

Patches & Fixes for CVE-2026-49981 (1)

Vendor Advisories for CVE-2026-49981 (1)

Vendor Pages for CVE-2026-49981 (1)

Same Patch Batch · twigphp · 2026-07-14 · 17 CVEs total

CVE-2026-466347.7 HIGHTwig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized templ
CVE-2026-47730Twig: XSS in profiler HtmlDumper via unescaped template and profile names
CVE-2026-47732Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
CVE-2026-48806Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
CVE-2026-48805Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
CVE-2026-48808Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterfa
CVE-2026-48807Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filte
CVE-2026-46635Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
CVE-2026-46638Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete f
CVE-2026-46628Twig: The `spaceless` filter implicitly marks its output as safe
CVE-2026-46640Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
CVE-2026-46637Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
CVE-2026-46639Twig: Sandbox property and method bypass via object-destructuring assignment
CVE-2026-46627Twig: Sandbox resource exhaustion via unbounded `for` / `range()`
CVE-2026-46633Twig: PHP code injection via `{% use %}` template name
CVE-2026-46629Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled argu

IV. Related Vulnerabilities

V. Comments for CVE-2026-49981

No comments yet


Leave a comment