PKSA-yd6k-t2gh-1m43 Security Advisory
-
Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders
PKSA-yd6k-t2gh-1m43 CVE-2026-46636
Affected package: twig/twig
Affected version: >=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.27.0
Reported by:
FriendsOfPHP/security-advisories