VYPR
Critical severity9.1OSV Advisory· Published Jul 14, 2026· Updated Jul 17, 2026

CVE-2026-48807

CVE-2026-48807

Description

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
twig/twigPackagist
< 3.27.03.27.0

Affected products

2
  • Twigphp/TwigOSV2 versions
    v3.26.0, v3.25.0, v3.24.0, …+ 1 more
    • (no CPE)range: v3.26.0, v3.25.0, v3.24.0, …
    • (no CPE)range: <3.27.0

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.