Junglewise Threat Intelligence

CVE-2026-49981: Twig sandbox allow-list bypass via template cache reuse

CVE-2026-49981 · Severity: high · CVSS 4 · Published 2026-07-14

Technologies: Twig PHP Twig, twig/twig (Packagist). Vendors: Twig PHP, Packagist.

Executive brief

Twig, a popular template engine for PHP, contains a security flaw in its sandbox mode. The sandbox is designed to safely run untrusted code by restricting which functions and tags can be used; however, a caching error allows these restrictions to be bypassed if the system switches between sandboxed and non-sandboxed modes. This could allow an attacker with limited access to execute unauthorized functions, potentially leading to data exposure or unauthorized actions within the application.

Technical details

A vulnerability in Twig's sandbox mechanism exists where the allow-list verdict for filters, tags, and functions is computed during Template construction and cached. Because Template instances are stored in the Environment's $loadedTemplates cache, the security verdict remains 'sticky' even if the sandbox state changes (e.g., enabling/disabling the sandbox or swapping security policies). In environments with long-lived workers (like FrankenPHP or RoadRunner), a template pre-warmed in a non-sandboxed context can be reused in a sandboxed context without re-verifying the security policy. This allows an attacker to bypass SecurityPolicy restrictions. The fix in version 3.27.0 moves the security check from the constructor to a new ensureSecurityChecked() method called during template execution.

Affected products

  • twigphp Twig < 3.27.0

Timeline

  • 2026-05-27: patched: Version 3.27.0 released
  • 2026-05-27: advisory: GitHub Security Advisory published
  • 2026-07-14: disclosed: NVD publication date

References

Related threats