CVE-2026-48807

CRITICAL

Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters

Title source: cna
STIX 2.1

Description

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/twigphp/Twig/releases/tag/v3.27.0

Scores

CVSS v3 9.1
EPSS 0.0022
EPSS Percentile 12.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-693 CWE-863
Status published
Products (2)
symfony/twig < 3.27.0
twigphp/Twig < 3.27.0
Published Jul 14, 2026
Tracked Since Jul 15, 2026