Critical severity9.8NVD Advisory· Published Jul 14, 2026· Updated Jul 16, 2026
CVE-2026-46633
CVE-2026-46633
Description
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
twig/twigPackagist | < 3.26.0 | 3.26.0 |
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/twigphp/Twig/commit/679447fa29083043665482ccf7d64372472621b8nvdPatch
- github.com/twigphp/Twig/commit/e9ff55f6910832428e48a35b2e0748189ad49ae3nvdPatch
- github.com/advisories/GHSA-7p85-w9px-jpjpghsaADVISORY
- github.com/twigphp/Twig/security/advisories/GHSA-7p85-w9px-jpjpnvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46633.yamlghsaWEB
- github.com/twigphp/Twig/releases/tag/v3.26.0nvdRelease Notes
- symfony.com/cve-2026-46633ghsaWEB
News mentions
0No linked articles in our index yet.