CVE-2026-47732

MEDIUM

Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points

Title source: cna
STIX 2.1

Description

Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operators, tests, template-loading tags, dynamic attribute names, spread arguments, the do tag, and the .. range operator. This issue is fixed in version 3.26.0.

Scores

CVSS v3 6.5
EPSS 0.0036
EPSS Percentile 28.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
symfony/twig < 3.26.0
twigphp/Twig < 3.26.0
Published Jul 14, 2026
Tracked Since Jul 15, 2026