{"id":"CVE-2026-47732","aliases":["GHSA-pr2w-4gpj-cpq4"],"url":"https://o3.security/vulnerability/CVE-2026-47732","summary":"Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points","details":"Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operators, tests, template-loading tags, dynamic attribute names, spread arguments, the do tag, and the .. range operator. This issue is fixed in version 3.26.0.","published":"2026-07-14T21:12:13.071Z","modified":"2026-08-12T03:51:31.790623685Z","cvss":null,"epss":{"score":0.0036,"percentile":0.2928,"asOf":"2026-08-20"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"twig/twig","fixedVersion":"3.26.0"}],"fix":{"url":"https://github.com/twigphp/Twig/commit/447d0b2331e01b8fc6e08119ac984e1ef50caef9","label":"twigphp/Twig@447d0b2"},"references":[{"type":"WEB","url":"https://github.com/twigphp/Twig/releases/tag/v3.26.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47732.json"},{"type":"ADVISORY","url":"https://github.com/twigphp/Twig/security/advisories/GHSA-pr2w-4gpj-cpq4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47732"},{"type":"FIX","url":"https://github.com/twigphp/Twig/commit/447d0b2331e01b8fc6e08119ac984e1ef50caef9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.790623685Z"}}