VDB
Sign up
HIGH

GHSA-mm6w-gr99-p3jj

Twig: Sandbox property and method bypass via object-destructuring assignment

Quick fix

GHSA-mm6w-gr99-p3jj — twig/twig: upgrade to the fixed version with the command below.

composer require twig/twig:^3.26.0

Details

### Description

The object-destructuring assignment syntax introduced in Twig 3.24.0 generates a call to `CoreExtension::getAttribute()` with the `$sandboxed` argument hardcoded to `false`, regardless of whether a `SandboxExtension` is active. This permanently disables the sandbox's property and method policy checks for every destructuring expression.

`ObjectDestructuringSetBinary::compile()` emits:

```php CoreExtension::getAttribute($this->env, $this->source, ..., \Twig\Template::ANY_CALL, false, false, false, ...); // ^^^^^ // sandbox check never runs ```

Whereas `GetAttrExpression::compile()` correctly passes `$env->hasExtension(SandboxExtension::class)`.

An attacker with write access to a sandboxed Twig template can read any public property or invoke any public getter on objects passed to the template engine, bypassing `SecurityPolicy` restrictions. The exploit requires only the `{% do %}` tag to be in `allowedTags`, which is a common configuration.

### Resolution

The destructuring compiler now forwards the active sandbox flag to `getAttribute()` so property/method allowlists are enforced.

### Credits

Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/twig/twig
Introduced in: 3.24.0Fixed in: 3.26.0
Fixcomposer require twig/twig:^3.26.0

References