Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-39261

25
FAUCET Score

CVE-2022-39261 is a path traversal vulnerability in the Twig template engine (versions 1.x < 1.44.7, 2.x < 2.15.3, 3.x < 3.4.3) that allows arbitrary file reading outside the template directory when user-supplied input is used in 'source' or 'include' statements with namespaces. This vulnerability affects products like Debian, Drupal, FedoraProject, and Symfony. With a CVSS score of 7.5 (High), this vulnerability has a network attack vector and low attack complexity, allowing an unauthenticated attacker to achieve high confidentiality impact by reading sensitive files. There is no integrity or availability impact. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, with only one article from SecurityWeek mentioning the Drupal patch.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, < 1.44.7CPE matchmatch criteria
cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
>= 2.0.0, < 2.15.3CPE matchmatch criteria
cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.4.3CPE matchmatch criteria
cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
>= 8.0.0, < 9.3.22CPE matchmatch criteria
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
>= 9.4.0, < 9.4.7CPE matchmatch criteria
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.35%
Probability of exploitation in next 30 days
EPSS Percentile
82.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0235 is in the 54th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

composerpatch availablevia ghsa
Product: twig/twigFixed in: 1.44.7
composerpatch availablevia ghsa
Product: twig/twigFixed in: 2.15.3
composerpatch availablevia ghsa
Product: twig/twigFixed in: 3.4.3
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-52m2-vc4m-jj33high

Twig may load a template outside a configured directory when using the filesystem loader

Sep 30, 2022

References

github.com / twigphp/Twig/commit/35f3035c5deb0041da7b84daf02dea074ddc7a0b
PatchThird Party Advisory
github.com / twigphp/Twig/security/advisories/GHSA-52m2-vc4m-jj33
Third Party Advisory
lists.debian.org / debian-lts-announce/2022/10/msg00016.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/2OKRUHPVLIQVFPPJ2UWC3WV3WQO763NR
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/AUVTXMNPSZAHS3DWZEM56V5W4NPVR6L7
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NWRFPZSR74SYVJKBTKTMYUK36IJ3SQJP
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/TW53TFJ6WWNXMUHOFACKATJTS7NIHVQE
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/WV5TNNJLGG536TJH6DLCIAAZZIPV2GUD
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/YU4ZYX62H2NUAKKGUES4RZIM4KMTKZ7F
debian.org / security/2022/dsa-5248
Third Party Advisory
drupal.org / sa-core-2022-016
PatchThird Party Advisory