{"id":"GHSA-4rmg-292m-wg3w","summary":"Smarty vulnerable to PHP Code Injection by malicious attribute in extends-tag","details":"### Impact\nTemplate authors could inject php code by choosing a malicous file name for an extends-tag. Users that cannot fully trust template authors should update asap.\n\n### Patches\nPlease upgrade to the most recent version of Smarty v4 or v5. There is no patch for v3.","aliases":["CVE-2024-35226"],"modified":"2025-11-05T01:01:54.522261Z","published":"2024-05-29T18:44:30Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-29T18:44:30Z","nvd_published_at":"2024-05-28T21:16:30Z","cwe_ids":["CWE-94"]},"references":[{"type":"WEB","url":"https://github.com/smarty-php/smarty/security/advisories/GHSA-4rmg-292m-wg3w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35226"},{"type":"WEB","url":"https://github.com/smarty-php/smarty/commit/0be92bc8a6fb83e6e0d883946f7e7c09ba4e857a"},{"type":"PACKAGE","url":"https://github.com/smarty-php/smarty"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/11/msg00013.html"}],"affected":[{"package":{"name":"smarty/smarty","ecosystem":"Packagist","purl":"pkg:composer/smarty/smarty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.1.1"}]}],"versions":["v5.0.0","v5.0.1","v5.0.2","v5.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-4rmg-292m-wg3w/GHSA-4rmg-292m-wg3w.json"}},{"package":{"name":"smarty/smarty","ecosystem":"Packagist","purl":"pkg:composer/smarty/smarty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"4.5.3"}]}],"versions":["v3.1.11","v3.1.12","v3.1.13","v3.1.14","v3.1.15","v3.1.16","v3.1.17","v3.1.18","v3.1.19","v3.1.20","v3.1.21","v3.1.23","v3.1.24","v3.1.25","v3.1.26","v3.1.27","v3.1.28","v3.1.29","v3.1.30","v3.1.31","v3.1.32","v3.1.33","v3.1.34","v3.1.35","v3.1.36","v3.1.37","v3.1.37.1","v3.1.38","v3.1.39","v3.1.40","v3.1.41","v3.1.42","v3.1.43","v3.1.44","v3.1.45","v3.1.46","v3.1.47","v3.1.48","v4.0.0","v4.0.0-rc.0","v4.0.1","v4.0.2","v4.0.3","v4.0.4","v4.1.0","v4.1.1","v4.2.0","v4.2.1","v4.3.0","v4.3.1","v4.3.2","v4.3.3","v4.3.4","v4.3.5","v4.4.0","v4.4.1","v4.5.0","v4.5.1","v4.5.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-4rmg-292m-wg3w/GHSA-4rmg-292m-wg3w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"}]}