PKSA-5k7f-wvjj-jrgw Security Advisory
-
[HIGH] Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
PKSA-5k7f-wvjj-jrgw CVE-2026-46640 GHSA-45vw-wh46-2vx8
Affected package: twig/twig
Affected version: >=3.15.0,<3.26.0
Reported by:
GitHub, FriendsOfPHP/security-advisories