High severity8.8NVD Advisory· Published Jul 14, 2026· Updated Jul 16, 2026
CVE-2026-46640
CVE-2026-46640
Description
Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.() and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template source and executed at template-load time. This issue is fixed in version 3.26.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
twig/twigPackagist | >= 3.15.0, < 3.26.0 | 3.26.0 |
Affected products
2- osv-coords2 versions
< 11.3.10-r0+ 1 more
- (no CPE)range: < 11.3.10-r0
- (no CPE)range: >= 3.15.0, < 3.26.0
Patches
Vulnerability mechanics
References
7- github.com/twigphp/Twig/commit/324fa60545694fa6abe85ded9befcb82e1066bc2nvdPatch
- github.com/advisories/GHSA-45vw-wh46-2vx8ghsaADVISORY
- github.com/twigphp/Twig/security/advisories/GHSA-45vw-wh46-2vx8nvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46640.yamlghsaWEB
- github.com/twigphp/Twig/releases/tag/v3.26.0nvdRelease Notes
- github.com/vladko312/extras/blob/main/CVE-2026-46640.pyghsaWEB
- symfony.com/cve-2026-46640ghsaWEB
News mentions
0No linked articles in our index yet.