THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f6wf-28g6-769x (medium) — Smarty: Symlink path traversal out of trusted directories

[GHSA] GHSA-f6wf-28g6-769x (medium) — Smarty: Symlink path traversal out of trusted directories

medgithub_advisoriesPublished 2026-08-07

GHSA-f6wf-28g6-769x Severity: medium CVE: CVE-2026-62992

Smarty: Symlink path traversal out of trusted directories

When Smarty's Security policy is enabled, secure_dir (and the configured template/trusted directories) restrict which local files a template may read via {include} and {fetch}. The trust check in Security::_checkDir() resolved the requested path with Smarty::_realpath(), which norma

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f6wf-28g6-769x