In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox to execute arbitrary PHP code when disablenativefuncs is true.
{
"nvd_published_at": "2022-03-28T11:15:00Z",
"severity": "CRITICAL",
"github_reviewed": true,
"cwe_ids": [],
"github_reviewed_at": "2022-03-30T19:57:38Z"
}