Skip to content

« Twig » blog posts

Updates and new features of the Twig template language used in Symfony and PHP applications.

XSS in profiler HtmlDumper via unescaped template and profile names
May 20, 2026 #Twig
Arbitrary PHP code execution via `_self.(
May 20, 2026 #Twig
`{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
May 20, 2026 #Twig
Sandbox property allowlist bypass via the `column` filter (array_column on objects)
May 20, 2026 #Twig
HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
May 20, 2026 #Twig
Sandbox property and method bypass via object-destructuring assignment
May 20, 2026 #Twig
Possible sandbox bypass when using a source policy
May 20, 2026 #Twig
Twig 3.26.0 released
May 20, 2026 #Twig ❤️ 2 🚀 3
Twig 3.25.0 ships with a new ``needs_is_sandboxed`` option that lets filters, functions, and tests adapt their behavior when running inside a sandbox, makes the compiled output of templates using ``{% embed %}`` deterministic across runs, and removes a long-standing limitation that prevented overriding ``EscaperRuntime`` via a custom runtime loader.
May 17, 2026 #Twig 👍 2 🚀 1
Twig 3.24.0 has just been released with a major new feature for working with HTML attributes, improved null-safe operator behavior, and variable renaming in object destructuring.
March 18, 2026 #Twig ❤️ 11 👍 5 🚀 12 🎉 5