
CVE-2026-71291 Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Fi… https://www.cve.org/CVERecord?id=CVE-2026-71291
Post summary
The text discloses that Bolt CMS uses Twig without sandboxing, describing a vulnerability, but it does not mention an exploit, patch, or active exploitation.

