Improper access control in Twig - CVE-2024-51755
Published: November 6, 2024 / Updated: May 20, 2026
Twig
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the sandbox attribute access handling when processing attributes of array-like objects. A remote privileged user can access attributes of array-like objects that are not checked by the security policy to disclose sensitive information.