CVE-2024-45411: Twig has a possible sandbox bypass

Published Sep 9, 2024
·
Updated

Description

Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions.

The security issue happens when all these conditions are met:

The sandbox is disabled globally; The sandbox is enabled via a sandboxed include() function which references a template name (like included.twig) and not a Template or TemplateWrapper instance; The included template has been loaded before the include() call but in a non-sandbox context (possible as the sandbox has been globally disabled).

Resolution

The patch ensures that the sandbox security checks are always run at runtime.

Credits

We would like to thank Fabien Potencier for reporting and fixing the issue.

Other sources

Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.

MITRE

Affected Software

8 affected componentsFixes available
composer/twig/twig>=3.0.0<3.11.1
3.11.1
composer/twig/twig>=3.12.0<3.14.0
3.14.0
composer/twig/twig>=2.0.0<2.16.1
2.16.1
composer/twig/twig>=1.0.0<1.44.8
1.44.8
Symfony Twig>=1.0.0<1.44.8
Symfony Twig>=2.0.0<2.16.1
Symfony Twig>=3.0.0<3.14.0
debian/php-twig<=2.14.3-1+deb11u2
2.14.3-1+deb11u33.5.1-1+deb12u13.20.0-2

Event History

Sep 9, 2024
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·08:19 PM
Apr 28, 2025
Data Sourced
via Ubuntu·04:40 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-45411?

CVE-2024-45411 is considered a critical vulnerability due to its potential to allow bypassing of sandbox restrictions.

2

How do I fix CVE-2024-45411?

To fix CVE-2024-45411, update the Twig package to versions 1.44.8, 2.16.1, 3.11.1, or 3.14.0.

3

What are the affected versions for CVE-2024-45411?

CVE-2024-45411 affects Twig versions below 1.44.8, 2.16.1, 3.11.1, and 3.14.0.

4

What conditions lead to the CVE-2024-45411 vulnerability?

The vulnerability occurs when the sandbox is globally disabled and managed incorrectly, allowing user-contributed templates to bypass security checks.

5

Who is impacted by CVE-2024-45411?

Users of the Twig templating engine who have disabled sandbox security checks are at risk for CVE-2024-45411.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203