Junglewise Threat Intelligence

CVE-2026-46634: Twig sandbox bypass via template_from_string in SourcePolicyInterface

CVE-2026-46634 · Severity: medium · CVSS 0 · Published 2026-07-14

Technologies: Twig PHP Twig, twig/twig (Packagist). Vendors: Twig PHP, Packagist.

Executive brief

Twig is a popular template engine for PHP used to generate dynamic web content. A security flaw exists where the 'sandbox' mode, designed to safely run untrusted code, can be bypassed if certain functions are enabled. An attacker with the ability to edit or provide templates could exploit this to bypass security restrictions, potentially leading to the theft of sensitive data or full control over the web server.

Technical details

A vulnerability in Twig's sandboxing mechanism occurs when the sandbox is enabled selectively via SourcePolicyInterface. When a sandboxed template calls template_from_string(), Twig compiles the new inner template using a synthesized name (e.g., __string_template__<hash>). Because this name does not match existing name-based or path-based security policies, the SourcePolicy returns false, causing the inner template's security checks to be bypassed. An attacker can leverage this to execute restricted functions, such as using the 'constant' function to read secrets or the 'map' filter with 'system' to achieve remote code execution. The issue is addressed in version 3.26.0 through updated documentation and warnings, as the vendor considers this a configuration trap; integrators are advised to never allow template_from_string in sandboxed environments.

Affected products

  • twigphp Twig >= 3.9.0, < 3.26.0

Timeline

  • 2026-05-20: patched: Version 3.26.0 released
  • 2026-05-20: advisory: GitHub Security Advisory GHSA-24x9-r6q4-q93w published
  • 2026-07-14: disclosed: CVE-2026-46634 published to NVD

References

Related threats