High severity7.5OSV Advisory· Published Jul 14, 2026· Updated Jul 17, 2026
CVE-2026-48808
CVE-2026-48808
Description
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
twig/twigPackagist | < 3.27.0 | 3.27.0 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/twigphp/Twig/commit/09c6706407ed7b1cb2d7d1408004f811e47e0424nvdPatch
- github.com/advisories/GHSA-h8vq-8gpg-mhcgghsaADVISORY
- github.com/twigphp/Twig/security/advisories/GHSA-h8vq-8gpg-mhcgnvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-48808.yamlghsaWEB
- github.com/twigphp/Twig/releases/tag/v3.27.0nvdRelease NotesWEB
- symfony.com/blog/cve-2026-48808-sandbox-property-allowlist-bypass-via-the-column-filter-under-sourcepolicyinterfaceghsaWEB
News mentions
0No linked articles in our index yet.