Medium severity6.5OSV Advisory· Published Jul 14, 2026· Updated Jul 16, 2026
CVE-2026-46639
CVE-2026-46639
Description
Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template to read public properties or invoke public getters on objects passed to the template engine. This issue is fixed in version 3.26.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
twig/twigPackagist | >= 3.24.0, < 3.26.0 | 3.26.0 |
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-mm6w-gr99-p3jjghsaADVISORY
- github.com/twigphp/Twig/security/advisories/GHSA-mm6w-gr99-p3jjnvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46639.yamlghsaWEB
- github.com/twigphp/Twig/releases/tag/v3.26.0nvdRelease Notes
- symfony.com/cve-2026-46639ghsaWEB
News mentions
0No linked articles in our index yet.