CVE-2021-26119: Code Injection
Sandbox protection could be bypassed through access to an internal Smarty object that should have been blocked. Sites that rely on Smarty Security features should upgrade as soon as possible. Please upgrade to 3.1.39 or higher.
Other sources
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.templateobject can be accessed in sandbox mode.
templateobject Sandbox Escape PHP Code Injection
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26119?
CVE-2021-26119 is considered a critical vulnerability that allows sandbox protection to be bypassed.
How do I fix CVE-2021-26119?
To fix CVE-2021-26119, upgrade Smarty to version 3.1.39 or higher.
Which versions of Smarty are affected by CVE-2021-26119?
Smarty versions up to and including 3.1.38 are affected by CVE-2021-26119.
What systems are impacted by CVE-2021-26119?
CVE-2021-26119 affects systems using affected versions of Smarty, including various Debian releases.
What features are compromised due to CVE-2021-26119?
CVE-2021-26119 compromises Smarty's security features by allowing unauthorized access to internal Smarty objects.