Skip to main content
Loading…
    CVE-2026-24425 — Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP — CVE Database · The Intelligence Room