Sensitive information sent insecurely In twig/twig

Description

Twig Sandbox Information Disclosure A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions
FLAT-MLXUH – Vulnerability | Fluid Attacks Database