PatchSiren

smarty-php CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM smarty-php CVE published 2026-08-07

CVE-2026-62992

CVE-2026-62992 is a vulnerability in Smarty, a template engine for PHP. An attacker could exploit this vulnerability to read arbitrary files accessible to the PHP process by bypassing the containment check using a symlink within a directory Smarty treats as trusted. This issue affects Smarty versions prior to 5.8.2 and 4.5.7. Defenders should assess exposure and prioritize verification and remediation eff [truncated]