{"id":"CVE-2026-46633","aliases":["GHSA-7p85-w9px-jpjp"],"url":"https://o3.security/vulnerability/CVE-2026-46633","summary":"Twig: PHP code injection via `{% use %}` template name","details":"Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.","published":"2026-07-14T21:14:24.916Z","modified":"2026-08-12T03:51:40.172283658Z","cvss":null,"epss":{"score":0.00642,"percentile":0.47816,"asOf":"2026-08-18"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"twig/twig","fixedVersion":"3.26.0"}],"fix":{"url":"https://github.com/twigphp/Twig/commit/679447fa29083043665482ccf7d64372472621b8","label":"twigphp/Twig@679447f"},"references":[{"type":"WEB","url":"https://github.com/twigphp/Twig/releases/tag/v3.26.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46633.json"},{"type":"ADVISORY","url":"https://github.com/twigphp/Twig/security/advisories/GHSA-7p85-w9px-jpjp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46633"},{"type":"FIX","url":"https://github.com/twigphp/Twig/commit/679447fa29083043665482ccf7d64372472621b8"},{"type":"FIX","url":"https://github.com/twigphp/Twig/commit/e9ff55f6910832428e48a35b2e0748189ad49ae3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:40.172283658Z"}}