{"id":"CVE-2026-46636","aliases":["GHSA-64jr-qjx4-w2fh"],"url":"https://o3.security/vulnerability/CVE-2026-46636","summary":"Twig: Sandbox method allowlist bypass via `Markup` subclass","details":"Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\\Markup. Twig\\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0.","published":"2026-09-04T22:07:35.122Z","modified":"2026-09-06T03:45:54.804568507Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"http://github.com/twigphp/Twig/releases/tag/v3.27.0"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/CVE-2026-46636"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/DSA-6311-1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46636.json"},{"type":"ADVISORY","url":"https://github.com/twigphp/Twig/security/advisories/GHSA-64jr-qjx4-w2fh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46636"},{"type":"ARTICLE","url":"https://symfony.com/blog/cve-2026-46636-sandbox-filter-tag-and-function-allow-list-bypass-when-sandbox-state-changes-between-renders"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-06T03:45:54.804568507Z"}}