GHSA-5mv2-rx3q-4w2v
GitHub Security Advisory
Code injection in Twig
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
# Description
When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions.
# Resolution
We now disallow calling non Closure in the `sort` filter like we already did for some other filters.
# Credits
We would like to thank Marlon Starkloff for reporting the issue and Fabien Potencier for fixing the issue.
Affected Packages
Packagist
twig/twig
Affected versions:
2.0.0
(fixed in 2.14.11)
Packagist
twig/twig
Affected versions:
3.0.0
(fixed in 3.3.8)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 15, 2025 6:32 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.