Количество 4
Количество 4
CVE-2026-46639
Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template to read public properties or invoke public getters on objects passed to the template engine. This issue is fixed in version 3.26.0.
CVE-2026-46639
Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template to read public properties or invoke public getters on objects passed to the template engine. This issue is fixed in version 3.26.0.
CVE-2026-46639
Twig is a template language for PHP. From 3.24.0 until 3.26.0, object- ...
GHSA-mm6w-gr99-p3jj
Twig: Sandbox property and method bypass via object-destructuring assignment
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-46639 Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template to read public properties or invoke public getters on objects passed to the template engine. This issue is fixed in version 3.26.0. | CVSS3: 6.5 | 0% Низкий | 28 дней назад | |
CVE-2026-46639 Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template to read public properties or invoke public getters on objects passed to the template engine. This issue is fixed in version 3.26.0. | CVSS3: 6.5 | 0% Низкий | 28 дней назад | |
CVE-2026-46639 Twig is a template language for PHP. From 3.24.0 until 3.26.0, object- ... | CVSS3: 6.5 | 0% Низкий | 28 дней назад | |
GHSA-mm6w-gr99-p3jj Twig: Sandbox property and method bypass via object-destructuring assignment | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу