Junglewise Threat Intelligence

CVE-2026-48808: Twig sandbox bypass in column filter via SourcePolicyInterface

CVE-2026-48808 · Severity: medium · CVSS 0 · Published 2026-07-14

Technologies: Twig PHP Twig, twig/twig (Packagist). Vendors: Twig PHP, Packagist.

Executive brief

Twig is a popular template engine for PHP used to generate dynamic web content. A security flaw in the 'column' filter allows template authors to bypass sandbox restrictions and access sensitive object properties that should be protected. This could lead to the unauthorized exposure of internal data or configuration details if an application allows users to provide their own templates.

Technical details

A vulnerability exists in Twig's CoreExtension::column() filter where the active sandbox state is passed as a boolean but the current Source context is not forwarded to SandboxExtension::checkPropertyAllowed(). When sandboxing is managed via SourcePolicyInterface, the missing Source context causes the security check to default to a non-sandboxed state, bypassing the property allowlist. This allows an attacker with template authorship privileges to access any public or magic property of objects within the render context. The issue is specific to SourcePolicyInterface-driven sandboxing and does not affect global sandbox mode. A fix is available in version 3.27.0.

Affected products

  • twigphp Twig < 3.27.0

Timeline

  • 2026-05-27: patched: Version 3.27.0 released
  • 2026-05-27: advisory: GitHub Security Advisory published
  • 2026-07-14: disclosed: CVE published to NVD

References

Related threats