Critical PHP Injection Vulnerability Patched in Twig Template Engine
A critical vulnerability in Twig versions prior to 3.26.0 allows attackers to inject arbitrary PHP code via crafted template names in {% use %} tags.
A critical security vulnerability, identified as CVE-2026-46633, has been discovered in the Twig template language for PHP. The flaw exists in the Compiler::string() method, which fails to properly escape single quotes when handling template names used within {% use %} tags. This oversight allows a crafted template name to terminate a PHP single-quoted string literal, enabling the injection of arbitrary PHP expressions into the compiled cache file.
With a CVSS score of 9.8, this vulnerability is classified as critical, as it allows for unauthorized code execution with high impact on confidentiality, integrity, and availability. The issue affects all versions of Twig prior to 3.26.0. Users are strongly advised to update their Twig installations to version 3.26.0 or later to mitigate this risk.
Sources
- NVD Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.