THREAT OPS › Threat News › [GHSA] GHSA-rjhh-76wf-8xmw (medium) — Smarty Security stream restriction bypass through stream: resource
[GHSA] GHSA-rjhh-76wf-8xmw (medium) — Smarty Security stream restriction bypass through stream: resource
GHSA-rjhh-76wf-8xmw Severity: medium CVE: CVE-2026-62996
Smarty Security stream restriction bypass through stream: resource
`smarty/smarty` version `5.8.0` can read local files through PHP stream wrappers even when Smarty Security is enabled and all streams are disabled with `Security::$streams = null`.
The bypass uses Smarty's built-in `stream:` resource type. A template such as:
```smarty {i
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- 78d259d3b971c59a0cd719c270cc5cbb740c36a7sha1
- CVE-2026-62996cve
Original source: https://github.com/advisories/GHSA-rjhh-76wf-8xmw