PT-2026-42635 · Packagist · Twig/Twig
Publicado
2026-05-21
·
Atualizado
2026-05-21
CVSS v4.0
8.7
Alta
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Description
The object-destructuring assignment syntax introduced in Twig 3.24.0 generates a call to
CoreExtension::getAttribute() with the $sandboxed argument hardcoded to false, regardless of whether a SandboxExtension is active. This permanently disables the sandbox's property and method policy checks for every destructuring expression.ObjectDestructuringSetBinary::compile() emits:php
CoreExtension::getAttribute($this->env, $this->source, ..., TwigTemplate::ANY CALL, false, false, false, ...);
// ^^^^^
// sandbox check never runsWhereas
GetAttrExpression::compile() correctly passes $env->hasExtension(SandboxExtension::class).An attacker with write access to a sandboxed Twig template can read any public property or invoke any public getter on objects passed to the template engine, bypassing
SecurityPolicy restrictions. The exploit requires only the {% do %} tag to be in allowedTags, which is a common configuration.Resolution
The destructuring compiler now forwards the active sandbox flag to
getAttribute() so property/method allowlists are enforced.Credits
Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue.
Exploit
Correção
Protection Mechanism Failure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Twig/Twig