Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. twig/twig
  4. ›
  5. CVE-2026-48805

CVE-2026-48805: Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`

June 30, 2026

The 3.26.0 source-policy hardening changed the signature of CoreExtension::checkArrow() to take a boolean $isSandboxed instead of an Environment, and added the same $isSandboxed argument to CoreExtension::arraySome() and CoreExtension::arrayEvery(). Compiled templates were updated to pass the per-source sandbox state computed at the call site.

The deprecated internal wrappers exposed in src/Resources/core.php for legacy third-party code (twig_check_arrow_in_sandbox(), twig_array_some(), twig_array_every()) were not updated:

  • twig_array_some() and twig_array_every() call CoreExtension::arraySome() / arrayEvery() without forwarding the sandbox state. The underlying methods default $isSandboxed to false, so the callable-must-be-a-Closure restriction is silently bypassed in sandbox mode and a string callable such as 'strcmp' is accepted.
  • twig_check_arrow_in_sandbox() passes the Environment object where CoreExtension::checkArrow() now expects a bool, which throws a TypeError on PHP 8+.

Compiled Twig templates are not affected: they call CoreExtension::* directly with the correct arguments. Applications are only impacted if they still call the deprecated twig_* helpers on top of a sandboxed Environment.

References

  • github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-48805.yaml
  • github.com/advisories/GHSA-p42q-9prx-q5wq
  • github.com/twigphp/Twig/releases/tag/v3.27.0
  • github.com/twigphp/Twig/security/advisories/GHSA-p42q-9prx-q5wq
  • nvd.nist.gov/vuln/detail/CVE-2026-48805
  • symfony.com/blog/cve-2026-48805-sandbox-state-regression-in-deprecated-internal-wrappers-in-src-resources-core-php

Code Behaviors & Features

Detect and mitigate CVE-2026-48805 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.27.0

Fixed versions

  • 3.27.0

Solution

Upgrade to version 3.27.0 or above.

Weakness

  • CWE-693: Protection Mechanism Failure

Source file

packagist/twig/twig/CVE-2026-48805.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 19 Jul 2026 12:17:13 +0000.