Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6311-1 | php-twig security update |
Github GHSA |
GHSA-24x9-r6q4-q93w | Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name |
Wed, 29 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Jul 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Twigphp
Twigphp twig |
|
| Vendors & Products |
Twigphp
Twigphp twig |
Tue, 14 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and include to render an inner template without security policy enforcement. This issue is fixed in version 3.26.0. | |
| Title | Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name | |
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-29T18:26:17.523Z
Reserved: 2026-05-15T20:11:54.583Z
Link: CVE-2026-46634
Updated: 2026-07-29T18:24:03.183Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T03:15:03Z
-
CWE-693
Protection Mechanism Failure
Debian DSA
Github GHSA