CVE-2026-82531
Smarty template cache code injection via extends inheritance
GHSA-3w63-v7pm-cq9x: Smarty before 4.5.8 and 5.x before 5.8.5 can leave nocache_hash null on extends:/multi-component inheritance so forged SmartyNocache markers in assigned data are written into regenerated PHP cache files and execute on include. CVSS 4.0 9.2. Public PoC exists. Not in CISA KEV.
- CVSS
- 9.2
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- Class
- RCE
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- smarty-php
- Products
- Smarty (Composer smarty/smarty)
- Affected
- All versions before 4.5.8, and 5.0.0 through 5.8.4 inclusive, per GHSA-3w63-v7pm-cq9x and the VulnCheck CVE record.
- Fixed
- 4.5.8 and 5.8.5 (and later on those major lines). Delete or regenerate existing template cache files after upgrading.
- CWE
- CWE-94
- Published
- 6 Oct 2026
- Updated
- 7 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-82531 is a code-injection vulnerability in the Smarty PHP template engine (Composer package smarty/smarty), tracked as GitHub Security Advisory GHSA-3w63-v7pm-cq9x and assigned through VulnCheck. During extends: / multi-component template inheritance, the top-level compiled nocache_hash is never restored and remains null. When template cache is regenerated, that null hash is folded into the nocache-marker regular expression as an empty alternative, so attacker-controlled assigned data can forge a SmartyNocache marker. Content inside the forged marker is copied verbatim into the generated PHP cache file, bypassing the PHP-tag neutralization applied to ordinary output. The next include() of that cache file executes the injected PHP, yielding remote code execution (CWE-94).
VulnCheck scores CVSS 4.0 9.2 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N and also publishes CVSS 3.1 8.1 (High) with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Affected versions are before 4.5.8 and 5.0.0 through versions before 5.8.5; fixed releases are 4.5.8 and 5.8.5. Realistic preconditions in the advisory include caching enabled, escape_html left off (Smarty default), inheritance templates, attacker-influenced assigned values echoed unescaped, and a cache regeneration while compiled templates remain on disk. NVD status is Awaiting Analysis. CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to poc.
GitHub user murrez published a public Python repository for CVE-2026-82531. The README describes a warm → clear-cache → poison → trigger chain against applications using extends inheritance and template caching, and claims remote code execution verified with a response marker. ThreatWire did not run it. The publisher’s account hosts many recent CVE-titled exploit repositories, which is a packaging red flag but does not by itself disprove that this repo’s prose matches GHSA-3w63-v7pm-cq9x. Availability is therefore PoC. This record does not reprint markers, payloads, or exploit commands.