Twig Template Engine: Single Quote Escape Bypass in PHP Code Generation
A missing single-quote escape in Twig's Compiler::string() method allows attackers to break out of PHP string literals via malicious {% use %} template names, achieving unauthenticated remote code execution even in sandboxed environments.