CVE-2026-24425

HIGH

Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface

Title source: cna
STIX 2.1

Description

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.

References (3)

Core 3

Scores

CVSS v3 8.8
EPSS 0.0011
EPSS Percentile 28.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-693
Status published
Products (2)
twigphp/Twig 2.16.*
twigphp/Twig 3.9.0 - 3.26.0
Published May 20, 2026
Tracked Since May 20, 2026