{"id":"CVE-2015-7809","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-7809","summary":"The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.","details":"The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.","published":"2015-11-06T21:59:12.580","modified":"2026-06-17T00:33:10.670","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/fabpot/Twig/commit/30be07759a3de2558da5224f127d052ecf492e8f","label":"fabpot/Twig@30be077"},"references":[{"type":"WEB","url":"http://openwall.com/lists/oss-security/2015/08/21/3"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2015/10/11/2"},{"type":"ADVISORY","url":"http://symfony.com/blog/security-release-twig-1-20-0"},{"type":"WEB","url":"http://www.debian.org/security/2015/dsa-3343"},{"type":"WEB","url":"https://github.com/fabpot/Twig/commit/30be07759a3de2558da5224f127d052ecf492e8f"},{"type":"WEB","url":"https://github.com/twigphp/Twig/pull/1759"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2015/08/21/3"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2015/10/11/2"},{"type":"ADVISORY","url":"http://symfony.com/blog/security-release-twig-1-20-0"},{"type":"WEB","url":"http://www.debian.org/security/2015/dsa-3343"},{"type":"WEB","url":"https://github.com/fabpot/Twig/commit/30be07759a3de2558da5224f127d052ecf492e8f"},{"type":"WEB","url":"https://github.com/twigphp/Twig/pull/1759"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T00:33:10.670"}}