Back to Database
Status published
High
CVE-2024-45411
Twig has a possible sandbox bypass
Vulnerability Description
Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-45411
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/twigphp/Twig/security/advisories/GHSA-6j75-5wfj-gh66
- https://github.com/twigphp/Twig/commit/11f68e2aeb526bfaf638e30d4420d8a710f3f7c6
- https://github.com/twigphp/Twig/commit/2102dd135986db79192d26fb5f5817a566e0a7de
- https://github.com/twigphp/Twig/commit/7afa198603de49d147e90d18062e7b9addcf5233
More from twigphp
View All →CVE-2025-24374
Twig fixes a security issue where escaping was missing when using null coalesce operator (??)
Medium
4.3
CVE-2024-51755
Unguarded calls to __isset() and to array-accesses when the sandbox is enabled in Twig
Low
2.2
CVE-2024-51754
Unguarded calls to __toString() when nesting an object into an array in Twig
Low
2.2
CVE-2022-39261
Twig may load a template outside a configured directory when using the filesystem loader
High
7.5
CVE-2022-23614
Code injection in Twig
High
8.8
Affected Vendor
twigphp
View all reports →Affected Software
Twig
Vulnerable Versions:
> 1.0.0, < 1.44.8, > 2.0.0, < 2.16.1, > 3.0.0, < 3.14.0
Timeline
Official Publish:
September 9th, 2024
Last Modified:
September 16th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H