# Description When using the sandbox with a `SourcePolicyInterface`, Twig does not always apply the sandbox restriction that forbids non-`Closure` callbacks for callback-accepting filters. The issue affects the `sort`, `filter`, `map`, and `reduce` filters. In the affected versions, the runtime check that rejects non-`Closure` callbacks in sandbox mode does not use the current template `Source`
GHSA: Twig: Possible
Exploit
CVE-2026-24425
GHSA