Executive brief
Twig, a PHP template engine used by web applications to render dynamic content safely, contains a sandbox security bypass affecting versions 1.0.0 through 3.26.x. The vulnerability allows template authors to access all public methods of custom objects derived from Twig\Markup, bypassing configured security restrictions that should limit what methods can be called. This could enable attackers with template-authoring capabilities to access sensitive methods and manipulate application behavior in ways the administrator did not intend.
Technical details
The SecurityPolicy::checkMethodAllowed() method unconditionally whitelists all method calls on Twig\Markup instances without checking the allowedMethods configuration. Because Twig\Markup is not declared final, subclasses inherit this bypass behavior, allowing any public method on derived classes to be called from sandboxed templates. An application passing a Markup-derived object into a sandboxed template inadvertently exposes the complete public method interface to template authors regardless of policy restrictions.
Affected products
- Twig Twig 1.0.0 to 3.26.x
Timeline
- 2026-09-04: disclosed
- 2026-05-27: patched: Fix released in v3.27.0