Skip to content

Symfony Blog

All about Symfony releases, new Symfony features, and other important announcements

Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments
HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
Sandbox does not protect against resource exhaustion
`{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
`template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
Sandbox property and method bypass via object-destructuring assignment
XSS in profiler HtmlDumper via unescaped template and profile names
Arbitrary PHP code execution via `_self.(
Sandbox property allowlist bypass via the `column` filter (array_column on objects)
Possible sandbox bypass when using a source policy