← Back to search

CVE-2026-71291

8.8 HIGHpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The flaw allows untrusted content to be executed as Twig templates, leading to Remote Code Execution (RCE) due to the lack of sandboxing.
Exploitability
Exploitation is moderately hard as it requires crafting a payload that triggers the allow_twig flag and includes malicious code.
Blast radius
If exploited, this could lead to full compromise of the affected system, including data theft and control of the server.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the allow_twig feature or update to the latest version of Bolt CMS that addresses this vulnerability.
rcewebcmstwigsandbox

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTwigValue calls shouldBeRenderedAsTwig, which gates rendering only on the field definition's allow_twig flag and a regex checking for , , or ; when true, the raw field value is compiled and rendered via with no sandboxing.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-1336

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.