{"id":"CVE-2026-48805","title":"Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`","summary":"Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`","severity":"low","cwe":["CWE-693"],"vendor":"twig","product":"twig/twig","ecosystem":"composer","affected":["twig/twig <= 3.26.0"],"patched":["twig/twig 3.27.0"],"published":"2026-06-30","updated":"2026-06-30","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-p42q-9prx-q5wq","references":[{"url":"https://github.com/twigphp/Twig/security/advisories/GHSA-p42q-9prx-q5wq"},{"url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-48805.yaml"},{"url":"https://github.com/twigphp/Twig/releases/tag/v3.27.0"},{"url":"https://symfony.com/blog/cve-2026-48805-sandbox-state-regression-in-deprecated-internal-wrappers-in-src-resources-core-php"},{"url":"https://github.com/advisories/GHSA-p42q-9prx-q5wq"}],"tags":["ghsa","composer"],"ingestedAt":"2026-06-30T21:24:14.393Z","epss":0.00483,"epssPercentile":0.38959,"slug":"CVE-2026-48805","body":"## Overview\n\n### Description\n\nThe 3.26.0 source-policy hardening changed the signature of `CoreExtension::checkArrow()` to take a boolean `$isSandboxed` instead of an `Environment`, and added the same `$isSandboxed` argument to `CoreExtension::arraySome()` and `CoreExtension::arrayEvery()`. Compiled templates were updated to pass the per-source sandbox state computed at the call site.\n\nThe deprecated internal wrappers exposed in `src/Resources/core.php` for legacy third-party code (`twig_check_arrow_in_sandbox()`, `twig_array_some()`, `twig_array_every()`) were not updated:\n\n- `twig_array_some()` and `twig_array_every()` call `CoreExtension::arraySome()` / `arrayEvery()` without forwarding the sandbox state. The underlying methods default `$isSandboxed` to `false`, so the callable-must-be-a-`Closure` restriction is silently bypassed in sandbox mode and a string callable such as `'strcmp'` is accepted.\n- `twig_check_arrow_in_sandbox()` passes the `Environment` object where `CoreExtension::checkArrow()` now expects a `bool`, which throws a `TypeError` on PHP 8+.\n\nCompiled Twig templates are not affected: they call `CoreExtension::*` directly with the correct arguments. Applications are only impacted if they still call the deprecated `twig_*` helpers on top of a sandboxed `Environment`.\n\n### Resolution\n\nThe three wrappers now resolve the current sandbox state via `twig_resolve_is_sandboxed()` (the same helper compiled templates use), and forward it to the corresponding `CoreExtension::*` method. `twig_check_arrow_in_sandbox()` no longer triggers a `TypeError`, and `twig_array_some()` / `twig_array_every()` now enforce the same sandbox restriction as compiled templates.\n\n### Credits\n\nWe would like to thank El Kharoubi Iosif for reporting the issue and Fabien Potencier for providing the fix.\n\n## Affected packages\n\n- `twig/twig <= 3.26.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `twig/twig 3.27.0`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}