CVE-2024-45411Protection Mechanism Failure in Twig

Severity
8.6HIGHNVD
CNA8.5
EPSS
0.1%
top 65.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9
Latest updateJun 2

Description

Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:NExploitability: 3.9 | Impact: 4.0

Affected Packages3 packages

Packagisttwig/twig1.0.01.44.8+3
NVDsymfony/twig1.0.01.44.8+2
CVEListV5twigphp/twig> 1.0.0, < 1.44.8, > 2.0.0, < 2.16.1, > 3.0.0, < 3.14.0+2

Patches

🔴Vulnerability Details

6
OSV
php-twig vulnerability2025-06-02
OSV
php-twig vulnerabilities2025-04-24
OSV
CVE-2024-45411: Twig is a template language for PHP2024-09-09
CVEList
Twig has a possible sandbox bypass2024-09-09
GHSA
Twig has a possible sandbox bypass2024-09-09

📋Vendor Advisories

3
Ubuntu
Twig vulnerability2025-06-02
Ubuntu
Twig vulnerabilities2025-04-24
Debian
CVE-2024-45411: php-twig - Twig is a template language for PHP. Under some circumstances, the sandbox secur...2024
CVE-2024-45411 — Protection Mechanism Failure in Twig | cvebase