{"id":"CVE-2026-46634","summary":"Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name","details":"Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__\u003chash\u003e name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and include to render an inner template without security policy enforcement. This issue is fixed in version 3.26.0.","aliases":["GHSA-24x9-r6q4-q93w"],"modified":"2026-07-31T03:33:42.300316859Z","published":"2026-07-14T21:19:17.804Z","related":["CGA-wv5f-4rvf-m364"],"database_specific":{"cwe_ids":["CWE-693"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46634.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/twigphp/Twig/releases/tag/v3.26.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46634.json"},{"type":"ADVISORY","url":"https://github.com/twigphp/Twig/security/advisories/GHSA-24x9-r6q4-q93w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46634"},{"type":"FIX","url":"https://github.com/twigphp/Twig/commit/1cde8f2b62463f85d47995fc25f8241cb409d915"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/twigphp/twig","events":[{"introduced":"47857eebb197745f66369b76c044a2359e3cc5b9"},{"fixed":"1fcae487b180d78e6351f4e0afa91f9eab96a2bc"},{"fixed":"1cde8f2b62463f85d47995fc25f8241cb409d915"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.9.0"},{"fixed":"3.26.0"}]}}],"versions":["v3.25.0","v3.24.0","v3.23.0","v3.22.2","v3.22.1","v3.22.0","v3.21.1","v3.21.0","v3.20.0","v3.19.0","v3.18.0","v3.17.1","v3.17.0","v3.16.0","v3.15.0","v3.14.0","v3.11.0","v3.13.0","v3.12.0","v3.10.3","v3.10.2","v3.10.1","v3.10.0","v3.9.3","v3.9.2","v3.9.1","v3.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46634.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}