Beveiligingsadvies

CVE-2026-46633

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-14 21:14:24
Laatst bijgewerkt 2026-07-16 03:55:36
Toegewezen door GitHub_M
CVSS-score 8.7
Status PUBLISHED

Beschrijving

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.