CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-48806

Critical · CVSS 9.1
CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-693, CWE-863

Description

Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in version 3.27.0.

Affected packages

Packagist twig/twig 0 → 3.27.0

References

Status: profiled · ingested 2026-07-17T06:00:46.000Z