🔐 CVE-2026-46634: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name ➡️ https://symfony.com/blog/cve-2026-46634-template-from-string-escapes-a-sourcepolicy-driven-sandbox-via-synthesized-template-name
Post summary
The Symfony blog post announces CVE‑2026‑46634, detailing how `template_from_string()` can escape a SourcePolicy‑controlled sandbox through a synthesized template name.

