Twig could be made to run programs if it received specially crafted network
traffic from an authenticated user.
Software Description:
- php-twig: Flexible, fast, and secure template engine for PHP
Details:
It was discovered that Twig did not properly validate PHP callables when
using a source policy. An authenticated user could possibly use this issue
to execute arbitrary code.
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
php-twig 3.23.0-2ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.https://ubuntu.com/security/notices/USN-8408-1
CVE-2026-24425
Get the latest Linux and open source security news straight to your inbox.