{"id":"CVE-2026-46639","aliases":["GHSA-mm6w-gr99-p3jj"],"url":"https://o3.security/vulnerability/CVE-2026-46639","summary":"Twig: Sandbox property and method bypass via object-destructuring assignment","details":"### Description\n\nThe object-destructuring assignment syntax introduced in Twig 3.24.0 generates a call to `CoreExtension::getAttribute()` with the `$sandboxed` argument hardcoded to `false`, regardless of whether a `SandboxExtension` is active. This permanently disables the sandbox's property and method policy checks for every destructuring expression.\n\n`ObjectDestructuringSetBinary::compile()` emits:\n\n```php\nCoreExtension::getAttribute($this->env, $this->source, ..., \\Twig\\Template::ANY_CALL, false, false, false, ...);\n//                                                                                ^^^^^\n//                                                                       sandbox check never runs\n```\n\nWhereas `GetAttrExpression::compile()` correctly passes `$env->hasExtension(SandboxExtension::class)`.\n\nAn attacker with write access to a sandboxed Twig template can read any public property or invoke any public getter on objects passed to the template engine, bypassing `SecurityPolicy` restrictions. The exploit requires only the `{% do %}` tag to be in `allowedTags`, which is a common configuration.\n\n### Resolution\n\nThe destructuring compiler now forwards the active sandbox flag to `getAttribute()` so property/method allowlists are enforced.\n\n### Credits\n\nTwig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue.","published":"2026-07-14T21:13:42.321Z","modified":"2026-08-12T03:51:36.521422003Z","cvss":null,"epss":{"score":0.00351,"percentile":0.28351,"asOf":"2026-08-20"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"twig/twig","fixedVersion":"3.26.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/twigphp/Twig/releases/tag/v3.26.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46639.json"},{"type":"ADVISORY","url":"https://github.com/twigphp/Twig/security/advisories/GHSA-mm6w-gr99-p3jj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46639"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46639.yaml"},{"type":"PACKAGE","url":"https://github.com/twigphp/Twig"},{"type":"WEB","url":"https://symfony.com/cve-2026-46639"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:36.521422003Z"}}