Shopware Map Function Vulnerability in Twig Security Extension Allowing Improper Closure Handling

Vulnerability

A vulnerability exists in Shopware versions 6.7.0.0 prior to 6.7.6.1, where a regression of a previous security fix allows crafted PHP Closures to bypass allowed function checks in the Twig security extension. This issue could lead to improper control over code execution in Twig-rendered views.

Impact

Exploitation of this vulnerability could allow unauthorized PHP Closure objects to be passed into the Twig 'map' function, potentially leading to arbitrary code execution.

Remediation

Users can upgrade to Shopware version 6.7.6.1 to address this vulnerability. Alternatively, the Shopware security plugin can be installed.

Added: Jan 14, 2026, 7:19 PM
Updated: Jan 14, 2026, 7:19 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
10.0
exploitability
5.6
remediation
7.7
relevance
2.1
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.