← العودة للجدول
CVE-2026-24425
CVE-2026-24425 — GHSA: Twig: Possible sandbox bypass when using a source policy
📅 2026-06-05
🟠 High 🔥 No GHSA Exploit Web CVSS 8.8 🎯 EPSS 0.11%

📋 الوصف الكامل

# Description When using the sandbox with a `SourcePolicyInterface`, Twig does not always apply the sandbox restriction that forbids non-`Closure` callbacks for callback-accepting filters. The issue affects the `sort`, `filter`, `map`, and `reduce` filters. In the affected versions, the runtime check that rejects non-`Closure` callbacks in sandbox mode does not use the current template `Source`

💻 الأنظمة المتأثرة

GHSA: Twig: Possible

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-24425

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←