Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-24425

Опубликовано: 20 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.8

Описание

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.

РелизСтатусПримечание
devel

pending

3.27.1-1
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-apps/resolute

released

3.23.0-2ubuntu0.1~esm1
jammy

not-affected

code not present
noble

not-affected

code not present
questing

ignored

end of life, was needed
resolute

needed

upstream

released

3.26.0-1

Показывать по

EPSS

Процентиль: 52%
0.00758
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.

CVSS3: 8.8
debian
3 месяца назад

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass ...

CVSS3: 8.8
github
3 месяца назад

Twig: Possible sandbox bypass when using a source policy

EPSS

Процентиль: 52%
0.00758
Низкий

8.8 High

CVSS3