CVE-2026-48807
published 2026-07-14CVE-2026-48807: Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters…
PriorityP348critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.37%
30.3th percentile
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| symfony | twig | < 3.27.0 | 3.27.0 |
| twig | twig | >= 0 < 3.27.0 | 3.27.0 |
| twigphp | twig | < 3.27.0 | 3.27.0 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
twigphp Twig __toString sandbox (CNNVD-2026-99532544)
vuldb·2026-07-15·CVSS 7.1
CVE-2026-48807 [HIGH] twigphp Twig __toString sandbox (CNNVD-2026-99532544)
A vulnerability was found in twigphp Twig and classified as critical. Affected by this vulnerability is the function __toString. The manipulation results in sandbox issue.
This vulnerability is known as CVE-2026-48807. Access to the local network is required for this attack. No exploit is available.
GHSA
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
ghsa·2026-06-30
CVE-2026-48807 [MEDIUM] CWE-693 Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
### Description
This is a residual bypass of CVE-2026-47732 / GHSA-pr2w-4gpj-cpq4 left after the initial fix for unguarded `__toString()` calls. It covers two related coercion points that were not caught by the original patch.
**`Traversable` in `join` and `replace` filters.** `SandboxExtension::ensureToStringAllowed()` recurses into PHP arrays so that a `Stringable` object hidden inside an array argument cannot be string-coerced without consulting the security policy. The recursion stops at PHP arrays: a `Traversable` value passed at the same position is not materialised, so its contents are not policy-checked. `CoreExtension::join()` and `CoreExtension::replace()` later materialise such `Trave
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-48807 phpMyAdmin: Twig: Sandbox bypass allows information disclosure [fedora-all]
bugzilla·2026-07-15·CVSS 7.1
CVE-2026-48807 [HIGH] CVE-2026-48807 phpMyAdmin: Twig: Sandbox bypass allows information disclosure [fedora-all]
CVE-2026-48807 phpMyAdmin: Twig: Sandbox bypass allows information disclosure [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.
Bugzilla
CVE-2026-48807 phpMyAdmin: Twig: Sandbox bypass allows information disclosure [epel-all]
bugzilla·2026-07-15·CVSS 7.1
CVE-2026-48807 [HIGH] CVE-2026-48807 phpMyAdmin: Twig: Sandbox bypass allows information disclosure [epel-all]
CVE-2026-48807 phpMyAdmin: Twig: Sandbox bypass allows information disclosure [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.
Bugzilla
CVE-2026-48807 twig/twig: Twig: Sandbox bypass allows information disclosure
bugzilla·2026-07-14·CVSS 7.1
CVE-2026-48807 [HIGH] CVE-2026-48807 twig/twig: Twig: Sandbox bypass allows information disclosure
CVE-2026-48807 twig/twig: Twig: Sandbox bypass allows information disclosure
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.
2026-07-14
Published