Improper access control in Twig - CVE-2024-51754
Published: November 6, 2024 / Updated: May 20, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the sandbox when processing objects in an array or an argument list. A remote privileged user can place an object in an array or argument list to disclose sensitive information.
The issue occurs when __toString() is invoked even though that method is not allowed by the security policy.
Affected software
Debian Linux
php-twig (Debian package)
How to mitigate CVE-2024-51754
php-twig (Debian package) - update to 3.5.1-1+deb12u3