CVE-2026-46633Disclosure(symfony / twig)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch symfony twig systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • twig

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 2 mentions (2026-05-22); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
twig

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-05-20: 1Mentions · 2026-05-22: 2Mentions · 2026-05-24: 1Mentions · 2026-06-07: 1Mentions · 2026-08-10: 1Mentions · 2026-09-21: 1PoC Mentioned / Linked · 2026-05-24: 1PoC Mentioned / Linked · 2026-09-21: 1Exploit Tool / Code · 2026-05-24: 1Exploit Tool / Code · 2026-09-21: 1Patch / Workaround · 2026-05-22: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-22: 2Technical Details · 2026-05-24: 1Technical Details · 2026-06-07: 1Technical Details · 2026-08-10: 105-2005-2205-2406-0708-1009-21
Signal classification5 categories
Disclosure
342.9%
Patch
114.3%
PoC
114.3%
General
114.3%
Exploit
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-201
Disclosure1
2026-05-222
Disclosure1Patch1
2026-05-241
PoC1
2026-06-071
General1
2026-08-101
Disclosure1
2026-09-211
Exploit1
Full discourse7 posts
  • Symfony@symfony
    Disclosure

    🔐 CVE-2026-46633: PHP code injection via `{% use %}` template name ➡️ https://symfony.com/blog/cve-2026-46633-php-code-injection-via-use-template-name

    Post summary

    The Symfony blog post announces CVE-2026-46633, describing PHP code injection via `{% use %}` template names, but does not provide PoC, exploit code, active exploitation evidence, or a patch.

    0101732.7K
    45.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Twig Template Engine PHP Code Injection (CVE-2026-46633) A critical code injection vulnerability in the Twig template engine allows unauthenticated remote attackers to execute arbitrary PHP code. The flaw stems from improper escaping within the template compiler when parsing a {% use %} tag. By including a single quote in a template name, an attacker can break out of the generated PHP single-quoted string context, injecting arbitrary PHP expressions into the compiled cache file. This completely bypasses the Twig sandbox and runs inside the PHP system process during cache evaluation. 👉 Affected: twig/twig (< 3.26.0) | Upgrade to version 3.26.0

    Post summary

    A critical Twig Template Engine vulnerability (CVE‑2026‑46633) permits remote code execution via improper escaping. Upgrade to Twig 3.26.0 to remediate.

    0002097
    196 followersView on X
  • vladko312@vladko312
    Exploit

    @GsInfosystems And with the AI-induced amount of CVEs it is even harder to separate exploitable ones from useless "technically a vuln" stuff. For example, I created the payload for CVE-2026-46640 and it was not as easy as AI might suggest. And for CVE-2026-46633 I have only partial success.

    Post summary

    The post reports that the author created a payload for CVE-2026-46640 and achieved only partial success with CVE-2026-46633, emphasizing the difficulty of distinguishing exploitable AI-generated CVEs from non-exploitable ones. It does not indicate active exploitation, patch availability, or detailed vulnerability characteristics.

    1000044
    8 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Disclosure

    Twig 3.26.0 未満のコードインジェクション CVE-2026-46633、CVSS 9.8。use タグのテンプレート名がシングルクォートをエスケープされず、コンパイル済みキャッシュに PHP 式が書き込めます。テンプレート名が外部入力から来る箇所があるかを先に gr… https://cve.autoarticles.net/cve/CVE-2026-46633

    Post summary

    The text discloses a high‑severity code injection vulnerability (CVE‑2026‑46633) in Twig versions below 3.26.0, explaining how an unescaped single quote in the `use` tag enables PHP expressions to be injected into compiled cache.

    0000065
    562 followersView on X
  • vladko312@vladko312
    General

    @watchtowrcyber It would be interesting to see your attempt to reproduce RCE using CVE-2026-46633. It has CVSSv4 of 9.3 and could act as RCE payload for most Twig versions, sandboxed or not, including previously unexploitable ones. Still, there are no known RCE payloads, unlike CVE-2026-46640.

    Post summary

    The tweet highlights the high CVSS score and RCE potential of CVE-2026-46633, but notes no known payloads or active exploits, with no mention of patches or PoC.

    00000164
    7 followersView on X
  • vladko312@vladko312
    PoC

    @AnthropicAI Mythos recently found multiple sandbox bypasses in Twig. For CVE-2026-46640, I made a PoC module for SSTImap, but it was not as trivial as the description might imply. As for CVE-2026-46633, I'm stuck after getting code injection. Can @AnthropicAI help prove it to be exploitable?

    Post summary

    The user reports sandbox bypasses in Twig and has created a PoC module for CVE-2026-46640, while seeking help to confirm exploitability of CVE-2026-46633; no evidence of active exploitation or patches is provided.

    0000087
    8 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 (Twig), Code Injection, #CVE-2026-46633 (Critical) https://dailycve.com/twig-code-injection-cve-2026-46633-critical/

    Post summary

    Announcement of a critical Twig code injection vulnerability (CVE-2026-46633).

    0000069
    207 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsymfonytwig---

Explore more