{"id":"CVE-2026-46640","aliases":["GHSA-45vw-wh46-2vx8"],"url":"https://o3.security/vulnerability/CVE-2026-46640","summary":"Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation","details":"### Description\n\nThe `obj.(expr)` dynamic-attribute syntax (added in 3.15.0 as the replacement for the deprecated `attribute()` function) lets the attribute be an arbitrary expression. When the receiver is `_self` (or any `{% import %}` alias) and the parenthesised expression is a string literal, `DotExpressionParser` short-circuits to the macro-call path and concatenates the attacker-controlled string into a `MacroReferenceExpression` name with no identifier validation. `MacroReferenceExpression::compile()` then emits that name raw into the generated PHP source.\n\nAn attacker who can supply template source can inject arbitrary PHP into the compiled template and execute it at template-load time, before `checkSecurity()` is ever called. This is a complete bypass of `SandboxExtension`, including a globally-enabled sandbox with an empty `SecurityPolicy` allowlist.\n\n### Resolution\n\nThe parser now validates that the dynamic attribute resolves to a valid macro identifier before routing through `MacroReferenceExpression`, and the macro-reference compiler emits the name through a properly escaped path.\n\n### Credits\n\nTwig would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.","published":"2026-07-14T21:22:57.332Z","modified":"2026-08-12T03:51:31.617983899Z","cvss":null,"epss":{"score":0.00405,"percentile":0.33685,"asOf":"2026-08-18"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"twig/twig","fixedVersion":"3.26.0"}],"fix":{"url":"https://github.com/twigphp/Twig/commit/324fa60545694fa6abe85ded9befcb82e1066bc2","label":"twigphp/Twig@324fa60"},"references":[{"type":"WEB","url":"https://github.com/twigphp/Twig/releases/tag/v3.26.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46640.json"},{"type":"ADVISORY","url":"https://github.com/twigphp/Twig/security/advisories/GHSA-45vw-wh46-2vx8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46640"},{"type":"FIX","url":"https://github.com/twigphp/Twig/commit/324fa60545694fa6abe85ded9befcb82e1066bc2"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-46640.yaml"},{"type":"PACKAGE","url":"https://github.com/twigphp/Twig"},{"type":"WEB","url":"https://github.com/vladko312/extras/blob/main/CVE-2026-46640.py"},{"type":"WEB","url":"https://symfony.com/cve-2026-46640"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.617983899Z"}}