CVE-2026-48808: Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Description
This is a residual bypass of CVE-2026-46635 / GHSA-vcc8-phrv-43wj that only affects sandboxing enabled through SourcePolicyInterface (and not the regular global sandbox mode).
CoreExtension::column() receives the active sandbox state via the needsissandboxed channel as a boolean $isSandboxed, but then routes the per-element property reads through SandboxExtension::checkPropertyAllowed() without forwarding the current Source. SandboxExtension::checkPropertyAllowed() re-evaluates isSandboxed($source) internally; with $source = null the SourcePolicyInterface-driven decision is lost, the method short-circuits to "not sandboxed", and the property allowlist is never consulted.
A template author whose sandbox is gated by a SourcePolicyInterface and who has column on their allowedFilters list can therefore read any public or magic property of any object reachable in the render context, regardless of SecurityPolicy::$allowedProperties. Direct attribute access to the same property is blocked, and the same payload is also blocked under global sandbox mode, which makes this a clear policy enforcement gap rather than a configuration issue.
Resolution
CoreExtension::column() no longer goes through the SandboxExtension wrapper for the property check. It calls the security policy directly: the per-source decision is already captured by the $isSandboxed boolean computed at the call site, so the property allowlist is enforced consistently for both global and source-policy sandboxing.
Credits
Twig would like to thank Vincent55 Yang for reporting the issue and Fabien Potencier for providing the fix.
Other sources
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/twig/twigto a version that resolves this vulnerability.Fixed in 3.27.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.27.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48808?
CVE-2026-48808 has a risk score of 40, indicating it is a moderate severity vulnerability.
How do I fix CVE-2026-48808?
To mitigate CVE-2026-48808, upgrade to Twig version 3.27.0 or later where the vulnerability is addressed.
What impact does CVE-2026-48808 have on my system?
CVE-2026-48808 can lead to a residual bypass in sandboxing environments enabled via the SourcePolicyInterface.
Which software is affected by CVE-2026-48808?
CVE-2026-48808 affects the composer/twig/twig software package.
When was CVE-2026-48808 published?
CVE-2026-48808 was published on June 30, 2026.