VDB
CVE-2026-24425
CVE-2026-24425
PUBLISHED
CVSS 8.699999809265137 HIGH
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.
EPSS 0.76% · 53.7th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.76%
53.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| twigphp | Twig | 3.9.0, 2.16.* |
Timeline
- May 20, 2026 PoC Published
- May 20, 2026 CVE Published
- May 20, 2026 PoC Published
- May 21, 2026 EPSS Score
- May 21, 2026 Coalition ESS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 25, 2026 Security Advisory
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score