PT-2026-42175 · Twig · Twig

Published

2026-05-20

·

Updated

2026-05-22

·

CVE-2026-46635

CVSS v4.0

2.1

Low

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Twig (affected versions not specified)
Description The column filter passes input directly to the native PHP array column() function. When array elements are objects, array column() reads properties directly, which bypasses the SandboxExtension::checkPropertyAllowed() check. This allows an untrusted template author with access to the column filter to read any public or magic property of any object within the render context, ignoring the allowedProperties list defined in the SecurityPolicy.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-46635
GHSA-VCC8-PHRV-43WJ

Affected Products

Twig