Executive brief
Twig, a popular template engine for PHP, contains a security flaw in its sandbox mode. The sandbox is designed to safely run untrusted code by restricting which functions and tags can be used; however, a caching error allows these restrictions to be bypassed if the system switches between sandboxed and non-sandboxed modes. This could allow an attacker with limited access to execute unauthorized functions, potentially leading to data exposure or unauthorized actions within the application.
Technical details
A vulnerability in Twig's sandbox mechanism exists where the allow-list verdict for filters, tags, and functions is computed during Template construction and cached. Because Template instances are stored in the Environment's $loadedTemplates cache, the security verdict remains 'sticky' even if the sandbox state changes (e.g., enabling/disabling the sandbox or swapping security policies). In environments with long-lived workers (like FrankenPHP or RoadRunner), a template pre-warmed in a non-sandboxed context can be reused in a sandboxed context without re-verifying the security policy. This allows an attacker to bypass SecurityPolicy restrictions. The fix in version 3.27.0 moves the security check from the constructor to a new ensureSecurityChecked() method called during template execution.
Affected products
- twigphp Twig < 3.27.0
Timeline
- 2026-05-27: patched: Version 3.27.0 released
- 2026-05-27: advisory: GitHub Security Advisory published
- 2026-07-14: disclosed: NVD publication date