All findings

CVE-2026-46633, CVE-2026-46639 critical

Twig 3.26.0 release credits Claude, Anvil Secure, and Claude Mythos

Twig's 3.26.0 security release includes critical and high advisories credited to Anvil Secure in collaboration with Claude and Anthropic Research, while the release notes also credit Claude Mythos Preview via Project Glasswing.

Bug class
Template sandbox bypass and PHP code injection
Affected codebase
Twig
Credited system
Claude / Anthropic Research
Disclosed
May 20, 2026
Attribution
Direct source attribution
Severity
critical
Source status: GitHub reviewed advisories for CVE-2026-46633 and CVE-2026-46639 directly credit Anvil Secure in collaboration with Claude and Anthropic Research. Twig's 3.26.0 release notes also credit Claude Mythos Preview via Project Glasswing at the broader release level; this entry counts only the two advisories with per-CVE Claude/Anvil mapping.

Summary

Twig 3.26.0 fixed 13 security advisories. Bugflation counts the two advisories where the public per-CVE record directly maps the issue to Anvil Secure in collaboration with Claude and Anthropic Research:

The release post additionally credits Claude Mythos Preview via Project Glasswing among reporters and fix authors, but it does not map every one of the 13 advisories to a specific AI-assisted reporter.

Attribution

This entry is direct but conservative. It counts the two per-CVE advisories with explicit Claude/Anvil credit and treats the broader Mythos release credit as contextual evidence rather than multiplying the count across all 13 fixes.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.