Source: smarty4
Version: 4.5.5-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for smarty4.

CVE-2026-62992[0]:
| Smarty is a template engine for PHP, facilitating the separation of
| presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and
| 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve
| symbolic links before validating that a requested path lies within a
| configured secure directory. An attacker able to place or reference
| a symlink within a directory Smarty treats as trusted (e.g., a
| template or config directory) could use it to point outside the
| intended secure directory, bypassing the containment check and
| reading arbitrary files accessible to the PHP process. This issue is
| fixed in versions 5.8.2 and 4.5.7.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-62992
    https://www.cve.org/CVERecord?id=CVE-2026-62992
[1] https://github.com/smarty-php/smarty/security/advisories/GHSA-f6wf-28g6-769x
[2] 
https://github.com/smarty-php/smarty/commit/a1ccdb0518021a559b4066c37b76a42c86bbce90

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to