We fixed with CVE-2023-2017 Twig filters to only be executed with allowed functions. However there was a regression that lead to an array and array crafted PHP Closure not checked being against allow list for the map(...) override
Patched in 6.7.6.1
Install the security plugin
{
"cwe_ids": [
"CWE-94"
],
"github_reviewed": true,
"github_reviewed_at": "2026-01-14T16:54:27Z",
"nvd_published_at": "2026-01-14T19:16:48Z",
"severity": "HIGH"
}