Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mm6w-gr99-p3jj

Опубликовано: 21 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

Twig: Sandbox property and method bypass via object-destructuring assignment

Description

The object-destructuring assignment syntax introduced in Twig 3.24.0 generates a call to CoreExtension::getAttribute() with the $sandboxed argument hardcoded to false, regardless of whether a SandboxExtension is active. This permanently disables the sandbox's property and method policy checks for every destructuring expression.

ObjectDestructuringSetBinary::compile() emits:

CoreExtension::getAttribute($this->env, $this->source, ..., \Twig\Template::ANY_CALL, false, false, false, ...); // ^^^^^ // sandbox check never runs

Whereas GetAttrExpression::compile() correctly passes $env->hasExtension(SandboxExtension::class).

An attacker with write access to a sandboxed Twig template can read any public property or invoke any public getter on objects passed to the template engine, bypassing SecurityPolicy restrictions. The exploit requires only the {% do %} tag to be in allowedTags, which is a common configuration.

Resolution

The destructuring compiler now forwards the active sandbox flag to getAttribute() so property/method allowlists are enforced.

Credits

Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue.

Пакеты

Наименование

twig/twig

composer
Затронутые версииВерсия исправления

>= 3.24.0, < 3.26.0

3.26.0

EPSS

Процентиль: 27%
0.00351
Низкий

8.7 High

CVSS4

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 6.5
ubuntu
28 дней назад

Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template to read public properties or invoke public getters on objects passed to the template engine. This issue is fixed in version 3.26.0.

CVSS3: 6.5
nvd
28 дней назад

Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template to read public properties or invoke public getters on objects passed to the template engine. This issue is fixed in version 3.26.0.

CVSS3: 6.5
debian
28 дней назад

Twig is a template language for PHP. From 3.24.0 until 3.26.0, object- ...

EPSS

Процентиль: 27%
0.00351
Низкий

8.7 High

CVSS4

Дефекты

CWE-693