Critical severity10.0NVD Advisory· Published Mar 28, 2022· Updated Jun 17, 2026
CVE-2021-46433
CVE-2021-46433
Description
In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox to execute arbitrary PHP code when disable_native_funcs is true.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
fenom/fenomPackagist | <= 2.12.1 | — |
Affected products
2- fenom/fenomdescription
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-674v-3g2w-84gxghsaADVISORY
- github.com/fenom-template/fenom/issues/331nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-46433ghsaADVISORY
News mentions
0No linked articles in our index yet.