Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.
CVSS Details
- CVSS 3.1 Base Score: 8.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade php-twig | Sep 17, 2024 | Sep 9, 2024 |
| Timber Library Plugin | — | Update timber-library plugin to version 1.23.3, or a newer patched version | Jul 25, 2025 | Jul 24, 2025 |
| Ubuntu | — | Upgrade php-twigUpgrade php-twig (Ubuntu Pro) | Apr 25, 2025 | Sep 9, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub