CVE-2026-46640: Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
Description
The obj.(expr) dynamic-attribute syntax (added in 3.15.0 as the replacement for the deprecated attribute() function) lets the attribute be an arbitrary expression. When the receiver is self (or any {% import %} alias) and the parenthesised expression is a string literal, DotExpressionParser short-circuits to the macro-call path and concatenates the attacker-controlled string into a MacroReferenceExpression name with no identifier validation. MacroReferenceExpression::compile() then emits that name raw into the generated PHP source.
An attacker who can supply template source can inject arbitrary PHP into the compiled template and execute it at template-load time, before checkSecurity() is ever called. This is a complete bypass of SandboxExtension, including a globally-enabled sandbox with an empty SecurityPolicy allowlist.
Resolution
The parser now validates that the dynamic attribute resolves to a valid macro identifier before routing through MacroReferenceExpression, and the macro-reference compiler emits the name through a properly escaped path.
Credits
Twig would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.
Other sources
Twig is a template language for PHP. From 3.15.0 until 3.26.0, self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template source and executed at template-load time. This issue is fixed in version 3.26.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/twig/twigto a version that resolves this vulnerability.Fixed in 3.26.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.26.0 - Compensating control
Until you can upgrade, avoid allowing attackers to supply template source that can use Twig macro-reference compilation involving `_self.(<string>)` / import-alias dynamic attribute syntax, since injected arbitrary PHP can execute at template-load time before `checkSecurity()` is called.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46640?
CVE-2026-46640 has a risk score of 85, indicating a high severity level.
What type of vulnerability is CVE-2026-46640?
CVE-2026-46640 is classified as a Code Injection vulnerability.
How do I fix CVE-2026-46640?
To mitigate CVE-2026-46640, ensure you are using a version of Twig that is updated to resolve this vulnerability.
What software is affected by CVE-2026-46640?
CVE-2026-46640 affects the composer/twig/twig library starting from version 3.15.0.
What are the implications of exploiting CVE-2026-46640?
Exploiting CVE-2026-46640 can lead to unauthorized code execution due to the dynamic attribute syntax allowing arbitrary expressions.