Critical severity9.1OSV Advisory· Published Jul 14, 2026· Updated Jul 17, 2026
CVE-2026-48806
CVE-2026-48806
Description
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in version 3.27.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
twig/twigPackagist | < 3.27.0 | 3.27.0 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/twigphp/Twig/commit/9ff41014639ef0e8eb50ac7669191c309d863105nvdPatch
- github.com/advisories/GHSA-5v5v-ww74-355vghsaADVISORY
- github.com/twigphp/Twig/security/advisories/GHSA-5v5v-ww74-355vnvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-48806.yamlghsaWEB
- github.com/twigphp/Twig/releases/tag/v3.27.0nvdRelease NotesWEB
- symfony.com/blog/cve-2026-48806-sandbox-tostring-policy-bypass-via-dynamic-mapping-keysghsaWEB
News mentions
0No linked articles in our index yet.