CVE-2026-46633 UNKNOWN

CVE-2026-46633

Published: 2026-07-14

Description

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…