Executive brief
Twig, a popular template engine for PHP, contains a security flaw in its sandbox mode. The sandbox is designed to restrict what template authors can do, but this vulnerability allows an author to bypass these restrictions by using specific objects as keys in a list. An attacker with the ability to edit templates could exploit this to view sensitive information that should otherwise be protected.
Technical details
A residual sandbox bypass exists in Twig's ArrayExpression component. When a dynamic key expression in a template resolves to a 'Stringable' object, PHP's engine performs a raw string cast during array construction. Because ArrayExpression failed to implement CoercesChildrenToStringInterface, the sandbox visitor did not wrap these nodes with CheckToStringNode. Consequently, SandboxExtension::ensureToStringAllowed() is never invoked, allowing a sandboxed template author to trigger __toString() on any object reachable in the render context. This results in unauthorized data disclosure. The issue is fixed in version 3.27.0 by ensuring dynamic mapping keys are treated as string-coercion sites.
Affected products
- twigphp Twig < 3.27.0
Timeline
- 2026-05-27: patched: Version 3.27.0 released
- 2026-05-27: advisory: GitHub Security Advisory published
- 2026-07-14: disclosed: CVE published to NVD