Protection Mechanism Failure
CVE-2026-24425
Summary
Twig versions 2.16.x and 3.9.0 through 3.25.0 contain a Sandbox Bypass vulnerability when using a 'SourcePolicyInterface' that allows attackers with template rendering capabilities to pass arbitrary PHP callables to 'sort', 'filter', 'map', and 'reduce' filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- HIGH
CWE-693 - Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
References
Advisory Timeline
- Published