StackRadar

CVE-2022-39261

High

Advisory

Published 28 Sept 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
84th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
71
of 17,781 indexed, latest versions
Container images
60
deployed by those charts
Fix available
2 of 2
affected packages

Twig may load a template outside a configured directory when using the filesystem loader

Carried by container images the latest versions of 71 of 17,781 indexed charts deploy, on 60 images.

Affected packageAffected versionsFixed inImages
twig/twigcomposerv1.35.0, v1.35.3, v1.42.5, v2.5.0+9 more1.44.7, 2.15.3, 3.4.360
drupal/corecomposer8.9.209.3.221
OSV records
GHSA-52m2-vc4m-jj33DRUPAL-CORE-2022-016
Also known as
BIT-drupal-2022-39261

Charts affected

71 by stars
ChartLatestAffected imagesRadar Score
orderregistratiecomponentorderregistratiecomponent1.0.01 of 3See more

orderregistratiecomponent orderregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
twig/twig@v2.13.1
2.15.3

Open the chart page →

7,492
firefly-iiiphntom0.2.101 of 2See more

firefly-iii phntom 0.2.10

1 of the 2 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
phntom/fireflyiii:version-5.7.5f881ea5fbbf1
twig/twig@v3.3.10
3.4.3

Open the chart page →

1,813
procestypecatalogusprocestypecatalogus1.1.01 of 4See more

procestypecatalogus procestypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
twig/twig@v2.13.1
2.15.3

Open the chart page →

7,429
productenendienstencatalogusproductenendienstencatalogus1.0.01 of 3See more

productenendienstencatalogus productenendienstencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
twig/twig@v2.13.1
2.15.3

Open the chart page →

7,510
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
twig/twig@v2.13.1
2.15.3

Open the chart page →

8,725
proto-component-commongroundproto-component-commonground1.0.01 of 3See more

proto-component-commonground proto-component-commonground 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
twig/twig@v2.13.1
2.15.3

Open the chart page →

7,510
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
twig/twig@v2.13.1
2.15.3

Open the chart page →

7,491
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
twig/twig@v3.3.3
3.4.3

Open the chart page →

2,972
mauticromholdings0.1.31 of 3See more

mautic romholdings 0.1.3

1 of the 3 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
twig/twig@v1.35.0
1.44.7

Open the chart page →

2,939
cachetsergiotocaliniVerified publisher1.0.01 of 1See more

cachet sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
twig/twig@v1.35.3
1.44.7

Open the chart page →

1,896
phpmyadminsitepilot1.0.11 of 1See more

phpmyadmin sitepilot 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.138437e021deb
twig/twig@v2.14.13
2.15.3

Open the chart page →

1,724
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
twig/twig@v2.13.1
2.15.3

Open the chart page →

7,480
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
twig/twig@v3.3.7
3.4.3

Open the chart page →

3,993
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
twig/twig@v2.13.1
2.15.3

Open the chart page →

7,510
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
twig/twig@v2.13.1
2.15.3

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
twig/twig@v2.13.1
2.15.3

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
twig/twig@v2.13.1
2.15.3

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
twig/twig@v2.13.1
2.15.3

Open the chart page →

7,429
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
twig/twig@v3.3.10
3.4.3

Open the chart page →

7,552
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
twig/twig@v3.3.3
3.4.3

Open the chart page →

2,534
satisfyymrs1.0.21 of 1See more

satisfy ymrs 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-39261.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
twig/twig@v2.5.0
2.15.3

Open the chart page →

1,572

Container images carrying it

60 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
twig/twig@v2.13.1
2.15.3
1
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
twig/twig@v2.13.1
2.15.3
1
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
twig/twig@v2.13.1
2.15.3
1
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
twig/twig@v2.13.1
2.15.3
1
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
twig/twig@v2.13.1
2.15.3
1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
twig/twig@v2.13.1
2.15.3
1
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
twig/twig@v2.13.1
2.15.3
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
twig/twig@v3.3.10
3.4.3
1
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
twig/twig@v3.3.3
3.4.3
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
twig/twig@v3.3.10
3.4.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.