Security Advisory

CVE-2026-46633

9.8
CRITICAL

Vulnerability Description

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.
Published Date July 14, 2026
Official Source NIST NVD Advisory