CVE-2026-24425: Twig: Possible sandbox bypass when using a source policy
When using the sandbox with a SourcePolicyInterface, Twig does not always apply the sandbox restriction that forbids non-Closure callbacks for callback-accepting filters.
The issue affects the sort, filter, map, and reduce filters.
In the affected versions, the runtime check that rejects non-Closure callbacks in sandbox mode does not use the current template Source. As a result, when the sandbox is enabled through a source policy instead of being enabled globally, Twig can incorrectly treat the current execution as non-sandboxed for these callback checks.
This can allow user-controlled templates to pass arbitrary PHP callables to callback-accepting filters even though the template is being sandboxed through a source policy.
The issue happens when all these conditions are met:
- The sandbox is not enabled globally;
- A
SourcePolicyInterfaceenables the sandbox for the rendered template; - The template uses one of the
sort,filter,map, orreducefilters; - The callback is not a
Closure.
References
- github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-24425.yaml
- github.com/advisories/GHSA-2q52-x2ff-qgfr
- github.com/twigphp/Twig/releases/tag/v3.26.0
- github.com/twigphp/Twig/security/advisories/GHSA-2q52-x2ff-qgfr
- nvd.nist.gov/vuln/detail/CVE-2026-24425
- symfony.com/cve-2026-24425
- www.vulncheck.com/advisories/twig-x-x-sandbox-bypass-via-sourcepolicyinterface
Code Behaviors & Features
Detect and mitigate CVE-2026-24425 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →