Junglewise Threat Intelligence

Duplicate Advisory: Craft CMS: Authenticated RCE through Twig sandbox escape

Severity: low · CVSS 3.1 · Published 2026-08-11

Technologies: craftcms/cms (Packagist). Vendors: Packagist.

Executive brief

Duplicate Advisory: Craft CMS: Authenticated RCE through Twig sandbox escape

Affected products

  • Packagist craftcms/cms

Related threats