Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-48808

Опубликовано: 14 июл. 2026
Источник: debian
EPSS Низкий

Описание

Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-twigfixed3.27.0-1package
php-twignot-affectedtrixiepackage
php-twignot-affectedbookwormpackage
php-twignot-affectedbullseyepackage

Примечания

  • https://symfony.com/blog/cve-2026-48808-sandbox-property-allowlist-bypass-via-the-column-filter-under-sourcepolicyinterface

EPSS

Процентиль: 15%
0.00239
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
27 дней назад

Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0.

CVSS3: 7.5
nvd
27 дней назад

Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0.

github
около 1 месяца назад

Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`

EPSS

Процентиль: 15%
0.00239
Низкий
Уязвимость CVE-2026-48808