CVE-2026-24425
Twig: Possible sandbox bypass when using a source policy
8.8
HIGH
CVSS 3.1
EPSS 0.74%
描述
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.
如何修補 CVE-2026-24425
要修補 CVE-2026-24425,請將受影響套件升級到下列已修補版本。
- —升級至 3.27.0-0+deb13u1 或更新版本
- —未列出修補版本
CVE-2026-24425 正在被利用嗎?
低 — EPSS 為 0.7%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 3.27.0-0+deb13u1
- >= 2.16.0, <= 2.16.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |