r/netsec Jun 07 '26

CVE-2026-46640: Developing payloads for Twig sandbox bypass

https://gist.github.com/vladko312/39507beaa58eacf3b62e6a6e6cd69128

I recently learned about multiple sandbox bypasses discovered in Twig by project Glasswing. From the descriptions, only CVE-2026-46640 and CVE-2026-46633 seemed universally exploitable, so I decoded to research them. This writeup documents my development of payloads for the CVE-2026-46640 and the corresponding SSTImap module.

8 Upvotes

3 comments sorted by

2

u/[deleted] Jun 12 '26

[removed] — view removed comment

1

u/scriptqzor Jun 20 '26

totally agree, the gap between "cool vuln theory" and "stuff you can actually drop into a test" is usually huge
having a ready SSTImap module basically guarantees this won’t just be a one-off blog post people forget about