Skip to content

Sandbox escape through template_object

High
wisskid published GHSA-w5hr-jm4j-9jvq Feb 21, 2021

Package

composer smarty/smarty (Composer)

Affected versions

<3.1.39

Patched versions

3.1.39

Description

Impact

Sandbox protection could be bypassed through access to an internal Smarty object that should have been blocked. Sites that rely on Smarty Security features should upgrade asap.

Patches

Please upgrade to 3.1.39 or higher.

References

See this article

For more information

If you have any questions or comments about this advisory please open an issue in the Smarty repo

Severity

High

CVE ID

CVE-2021-26119

Weaknesses

No CWEs

Credits