Smarty 2.6.19 Released
This release addresses a couple of bug fixes, and a bug with the regex_replace modifier that can allow php functions to be called in templates. If you use the security features of Smarty, you should upgrade immediately. As a quick fix, you can replace the modifier.regex_replace.php plugin with the new one.
ChangeLog here. download it here.