VYPR
Critical severity10.0NVD Advisory· Published Mar 28, 2022· Updated Jun 17, 2026

CVE-2021-46433

CVE-2021-46433

Description

In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox to execute arbitrary PHP code when disable_native_funcs is true.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
fenom/fenomPackagist
<= 2.12.1

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.