{"id":"CVE-2026-48806","title":"Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys","summary":"Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys","severity":"medium","cwe":["CWE-693","CWE-863"],"vendor":"twig","product":"twig/twig","ecosystem":"composer","affected":["twig/twig <= 3.26.0"],"patched":["twig/twig 3.27.0"],"published":"2026-06-30","updated":"2026-06-30","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-5v5v-ww74-355v","references":[{"url":"https://github.com/twigphp/Twig/security/advisories/GHSA-5v5v-ww74-355v"},{"url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2026-48806.yaml"},{"url":"https://github.com/twigphp/Twig/releases/tag/v3.27.0"},{"url":"https://symfony.com/blog/cve-2026-48806-sandbox-tostring-policy-bypass-via-dynamic-mapping-keys"},{"url":"https://github.com/advisories/GHSA-5v5v-ww74-355v"}],"tags":["ghsa","composer"],"ingestedAt":"2026-06-30T21:24:14.391Z","epss":0.00418,"epssPercentile":0.33384,"slug":"CVE-2026-48806","body":"## Overview\n\n### Description\n\nThis is a residual bypass of CVE-2026-47732 / GHSA-pr2w-4gpj-cpq4 left after the initial fix for unguarded `__toString()` calls.\n\nIn 3.26.0 the sandbox visitor was extended to wrap every child node that its parent will string-coerce at runtime with `CheckToStringNode`, gated by the new `CoercesChildrenToStringInterface`. `ArrayExpression` did not implement the interface for its mapping keys: when a dynamic key expression resolves to a `Stringable` object, `ArrayExpression::compile()` emits a raw `(string)` cast (via `StringCastUnary` for `ContextVariable` keys, and no cast at all for richer key expressions). PHP then invokes `__toString()` directly, without ever calling `SandboxExtension::ensureToStringAllowed()`.\n\nA sandboxed template author can therefore trigger `__toString()` on any object reachable in the render context by using it as a dynamic mapping key, for example:\n\n```twig\n{% set arr = {(obj): \"value\"} %}\n```\n\nDirect output of the same object is correctly blocked, which makes this a clear policy enforcement gap. The reliable demonstrated impact is unauthorised disclosure of data returned by `__toString()`.\n\n### Resolution\n\n`ArrayExpression` now declares its dynamic mapping keys as string-coercion sites through `CoercesChildrenToStringInterface`, so the sandbox visitor wraps them with `CheckToStringNode` and the policy is consulted before PHP coerces the key to a string. The compiler also keeps an explicit `(string)` cast around the wrapped expression so PHP type errors on non-string keys are preserved.\n\nAs a side effect, any expression is now accepted as a dynamic mapping key (not only context variables); this is documented as a new feature on the 3.x branch.\n\n### Credits\n\nTwig would like to thank El Kharoubi Iosif for reporting the issue and Fabien Potencier for providing the fix.\n\n## Affected packages\n\n- `twig/twig <= 3.26.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `twig/twig 3.27.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}