CVE Watchtower


← Back to CVE List

CVE-2026-46640NVD

Vulnerability Summary

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template source and executed at template-load time. This issue is fixed in version 3.26.0.
Severity Level
UNKNOWN
Published Date
May 21, 2026
Last Modified
Jul 16, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.41%Probability
Root Weakness (CWE)
N/A