CVE-2021-26119
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
Date published : 2021-02-21
https://security.gentoo.org/glsa/202105-06
https://github.com/smarty-php/smarty/blob/master/CHANGELOG.md