Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-45vw-wh46-2vx8

Опубликовано: 21 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

Twig: Arbitrary PHP code execution via _self.(<string>) macro-reference compilation

Description

The obj.(expr) dynamic-attribute syntax (added in 3.15.0 as the replacement for the deprecated attribute() function) lets the attribute be an arbitrary expression. When the receiver is _self (or any {% import %} alias) and the parenthesised expression is a string literal, DotExpressionParser short-circuits to the macro-call path and concatenates the attacker-controlled string into a MacroReferenceExpression name with no identifier validation. MacroReferenceExpression::compile() then emits that name raw into the generated PHP source.

An attacker who can supply template source can inject arbitrary PHP into the compiled template and execute it at template-load time, before checkSecurity() is ever called. This is a complete bypass of SandboxExtension, including a globally-enabled sandbox with an empty SecurityPolicy allowlist.

Resolution

The parser now validates that the dynamic attribute resolves to a valid macro identifier before routing through MacroReferenceExpression, and the macro-reference compiler emits the name through a properly escaped path.

Credits

Twig would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.

Пакеты

Наименование

twig/twig

composer
Затронутые версииВерсия исправления

>= 3.15.0, < 3.26.0

3.26.0

EPSS

Процентиль: 33%
0.00405
Низкий

8.7 High

CVSS4

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
ubuntu
28 дней назад

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template source and executed at template-load time. This issue is fixed in version 3.26.0.

CVSS3: 8.8
nvd
28 дней назад

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template source and executed at template-load time. This issue is fixed in version 3.26.0.

CVSS3: 8.8
debian
28 дней назад

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.( ...

EPSS

Процентиль: 33%
0.00405
Низкий

8.7 High

CVSS4

Дефекты

CWE-94