High severity7.5NVD Advisory· Published Sep 28, 2022· Updated Jun 17, 2026
CVE-2022-39261
CVE-2022-39261
Description
Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the source or include statement to read arbitrary files from outside the templates' directory when using a namespace like @somewhere/../some.file. In such a case, validation is bypassed. Versions 1.44.7, 2.15.3, and 3.4.3 contain a fix for validation of such template names. There are no known workarounds aside from upgrading.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
twig/twigPackagist | >= 1.0.0, < 1.44.7 | 1.44.7 |
twig/twigPackagist | >= 2.0.0, < 2.15.3 | 2.15.3 |
twig/twigPackagist | >= 3.0.0, < 3.4.3 | 3.4.3 |
Affected products
10cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- osv-coords2 versions
>= 8.0.0, < 9.3.22+ 1 more
- (no CPE)range: >= 8.0.0, < 9.3.22
- (no CPE)range: >= 1.0.0, < 1.44.7
Patches
Vulnerability mechanics
References
21- github.com/twigphp/Twig/commit/35f3035c5deb0041da7b84daf02dea074ddc7a0bnvdPatchThird Party AdvisoryWEB
- www.drupal.org/sa-core-2022-016nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-52m2-vc4m-jj33ghsaADVISORY
- github.com/twigphp/Twig/security/advisories/GHSA-52m2-vc4m-jj33nvdThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2022/10/msg00016.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-39261ghsaADVISORY
- www.debian.org/security/2022/dsa-5248nvdThird Party AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2022-39261.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/2OKRUHPVLIQVFPPJ2UWC3WV3WQO763NRghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/AUVTXMNPSZAHS3DWZEM56V5W4NPVR6L7ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/NWRFPZSR74SYVJKBTKTMYUK36IJ3SQJPghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/TW53TFJ6WWNXMUHOFACKATJTS7NIHVQEghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/WV5TNNJLGG536TJH6DLCIAAZZIPV2GUDghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/YU4ZYX62H2NUAKKGUES4RZIM4KMTKZ7FghsaWEB
- symfony.com/blog/twig-security-release-possibility-to-load-a-template-outside-a-configured-directory-when-using-the-filesystem-loaderghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2OKRUHPVLIQVFPPJ2UWC3WV3WQO763NR/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AUVTXMNPSZAHS3DWZEM56V5W4NPVR6L7/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NWRFPZSR74SYVJKBTKTMYUK36IJ3SQJP/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TW53TFJ6WWNXMUHOFACKATJTS7NIHVQE/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WV5TNNJLGG536TJH6DLCIAAZZIPV2GUD/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YU4ZYX62H2NUAKKGUES4RZIM4KMTKZ7F/nvd
News mentions
0No linked articles in our index yet.