Recent Commits to smarty:master

  • 29/06/2026 7:46

    Merge branch 'release/5.8.4'

    Merge branch 'release/5.8.4'
  • 29/06/2026 7:46

    version bump

    version bump
  • 29/06/2026 7:45

    Fix TypeError for non-array static_classes in Security policy (#1198)

    Fix TypeError for non-array static_classes in Security policy (#1198)
  • 29/06/2026 7:40

    drop unused version attribute from docker-compose.yml

    drop unused version attribute from docker-compose.yml
  • 29/06/2026 6:47

    Security: validate nested stream wrapper in stream: resource (CWE-22)…

    Security: validate nested stream wrapper in stream: resource (CWE-22) (#1195)
    
    The built-in stream: resource type let a template bypass Security stream
    restrictions. BasePlugin::load() matches the 'stream' sysplugin before the
    stream_get_wrappers()/isTrustedStream() check, so a resource such as
    stream:php://filter/read=convert.base64-encode/resource=/path was opened by
    StreamPlugin::getContent() via fopen() on the nested php:// wrapper without
    ever validating it. This bypassed Security::$streams (including
    Security::$streams = null) and allowed reading arbitrary local files.
    
    Parse the wrapper scheme from the resolved path in StreamPlugin::getContent()
    and validate it with Security::isTrustedStream() before fopen(), giving the
    stream: resource the same check the direct wrapper path already receives.
    
    Adds regression tests covering the disabled-streams bypass, the
    not-on-allowlist case, and a positive test that an explicitly allowed wrapper
    still works.
    Tags:

Log in