Threat Advisory

Smarty Flaw Lets Attackers Read Arbitrary Files

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting smarty/smarty versions >= 5.0.0, < 5.8.4 and < 4.5.7. The overall risk/impact is high due to arbitrary file read vulnerability.

CVE-2026-62992 (CVSS 6.9 — Severity): A symlink path traversal out of trusted directories allows an attacker able to cause a symlink to exist inside a trusted directory and cause a template to reference that path to read arbitrary files readable by the PHP process, escaping the secure_dir boundary.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting smarty/smarty versions >= 5.0.0, < 5.8.4 and < 4.5.7. The overall risk/impact is high due to arbitrary file read vulnerability.

CVE-2026-62992 (CVSS 6.9 — Severity): A symlink path traversal out of trusted directories allows an attacker able to cause a symlink to exist inside a trusted directory and cause a template to reference that path to read arbitrary files readable by the PHP process, escaping the secure_dir boundary.[emaillocker id="1283"]

CVE-2026-62996 (CVSS 6.9 — Severity): Smarty Security stream restriction bypass through stream: resource type allows an attacker to read local files through PHP stream wrappers even when Smarty Security is enabled and all streams are disabled with Security::$streams = null. These vulnerabilities collectively present a significant risk of arbitrary file access for developers using smarty/smarty. Administrators should review their exposure and ensure no untrusted symlinks can be created within any directory listed in secure_dir/the trusted template directories; restrict write access to those directories to trusted processes only. These vulnerabilities collectively present a significant risk of arbitrary file access for developers using smarty/smarty.

These vulnerabilities collectively present a significant risk of arbitrary file access for developers using smarty/smarty.

RECOMMENDATION:

We recommend you to update Smarty to version 5.8.2 or 4.5.7 or 5.8.4 depending on your installed branch.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu