Protection mechanism failure in Craft CMS - #VU139966
Published: July 29, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a protection mechanism failure in the Twig sandbox SecurityPolicy class when rendering a user-defined Twig template. A remote user can render a malicious Twig template to execute arbitrary code.
Exploitation requires permission to access the control panel, and the issue can be triggered even when the Twig sandbox is enabled through enableTwigSandbox().