THREAT OPS › Threat News › [GHSA] GHSA-f6wf-28g6-769x (medium) — Smarty: Symlink path traversal out of trusted directories
[GHSA] GHSA-f6wf-28g6-769x (medium) — Smarty: Symlink path traversal out of trusted directories
GHSA-f6wf-28g6-769x Severity: medium CVE: CVE-2026-62992
Smarty: Symlink path traversal out of trusted directories
When Smarty's Security policy is enabled, secure_dir (and the configured template/trusted directories) restrict which local files a template may read via {include} and {fetch}. The trust check in Security::_checkDir() resolved the requested path with Smarty::_realpath(), which norma
Indicators of compromise
- CVE-2026-62992cve
Original source: https://github.com/advisories/GHSA-f6wf-28g6-769x