Security Advisory
CVE-2026-46633
9.8
CRITICAL
Vulnerability Description
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.
Published Date
July 14, 2026
Official Source
NIST NVD Advisory