CVE-2026-24425

HIGH

Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface

Title source: cna
STIX 2.1

Description

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.

References (3)

Core 3

Scores

CVSS v3 8.8
EPSS 0.0076
EPSS Percentile 51.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-693
Status published
Products (5)
symfony/twig 2.16.0 - 2.16.1
twig/twig 2.16.0 - 2.16.1Packagist
twig/twig 3.9.0 - 3.26.0Packagist
twigphp/Twig 2.16.*
twigphp/Twig 3.9.0 - 3.26.0
Published May 20, 2026
Tracked Since May 20, 2026