Package impact
Packagist / twig/twig
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-24425 | critical | 9.9 | 9.9 | 15d ago | Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PH… | |||
| CVE-2026-46633 | critical | — | 9.5 | 15d ago | Twig: PHP code injection via `{% use %}` template name | |||
| CVE-2026-46628 | low | — | 2.5 | 15d ago | Twig: The `spaceless` filter implicitly marks its output as safe | |||
| CVE-2026-46635 | low | — | 2.5 | 15d ago | Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects) |