Summary
Twig 3.26.0 fixed 13 security advisories. Bugflation counts the two advisories where the public per-CVE record directly maps the issue to Anvil Secure in collaboration with Claude and Anthropic Research:
- CVE-2026-46633, critical PHP code injection through a
{% use %}template name. - CVE-2026-46639, high-severity sandbox property and method bypass via object-destructuring assignment.
The release post additionally credits Claude Mythos Preview via Project Glasswing among reporters and fix authors, but it does not map every one of the 13 advisories to a specific AI-assisted reporter.
Attribution
This entry is direct but conservative. It counts the two per-CVE advisories with explicit Claude/Anvil credit and treats the broader Mythos release credit as contextual evidence rather than multiplying the count across all 13 fixes.
References
- Twig 3.26.0 release
- GitHub Advisory: CVE-2026-46633
- GitHub Advisory: CVE-2026-46639
- Symfony advisory: CVE-2026-46639
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.