Loading HuntDB...

GHSA-5mv2-rx3q-4w2v

GitHub Security Advisory

Code injection in Twig

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

# Description

When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions.

# Resolution

We now disallow calling non Closure in the `sort` filter like we already did for some other filters.

# Credits

We would like to thank Marlon Starkloff for reporting the issue and Fabien Potencier for fixing the issue.

Affected Packages

Packagist twig/twig
Affected versions: 2.0.0 (fixed in 2.14.11)
Packagist twig/twig
Affected versions: 3.0.0 (fixed in 3.3.8)

Related CVEs

Key Information

GHSA ID
GHSA-5mv2-rx3q-4w2v
Published
February 10, 2022 10:21 PM
Last Modified
February 11, 2022 7:16 PM
CVSS Score
7.5 /10
Primary Ecosystem
Packagist
Primary Package
twig/twig
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.