Skip to content
THREATWIRE

CVE

CriticalPoC Available

CVE-2026-82531

Smarty template cache code injection via extends inheritance

GHSA-3w63-v7pm-cq9x: Smarty before 4.5.8 and 5.x before 5.8.5 can leave nocache_hash null on extends:/multi-component inheritance so forged SmartyNocache markers in assigned data are written into regenerated PHP cache files and execute on include. CVSS 4.0 9.2. Public PoC exists. Not in CISA KEV.

CVSS
9.2
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Class
RCE
Status
PoC Available
KEV
Not in CISA KEV
0-day
No
Vendor
smarty-php
Products
Smarty (Composer smarty/smarty)
Affected
All versions before 4.5.8, and 5.0.0 through 5.8.4 inclusive, per GHSA-3w63-v7pm-cq9x and the VulnCheck CVE record.
Fixed
4.5.8 and 5.8.5 (and later on those major lines). Delete or regenerate existing template cache files after upgrading.
Published
6 Oct 2026
Updated
7 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2026-82531 is a code-injection vulnerability in the Smarty PHP template engine (Composer package smarty/smarty), tracked as GitHub Security Advisory GHSA-3w63-v7pm-cq9x and assigned through VulnCheck. During extends: / multi-component template inheritance, the top-level compiled nocache_hash is never restored and remains null. When template cache is regenerated, that null hash is folded into the nocache-marker regular expression as an empty alternative, so attacker-controlled assigned data can forge a SmartyNocache marker. Content inside the forged marker is copied verbatim into the generated PHP cache file, bypassing the PHP-tag neutralization applied to ordinary output. The next include() of that cache file executes the injected PHP, yielding remote code execution (CWE-94).

VulnCheck scores CVSS 4.0 9.2 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N and also publishes CVSS 3.1 8.1 (High) with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Affected versions are before 4.5.8 and 5.0.0 through versions before 5.8.5; fixed releases are 4.5.8 and 5.8.5. Realistic preconditions in the advisory include caching enabled, escape_html left off (Smarty default), inheritance templates, attacker-influenced assigned values echoed unescaped, and a cache regeneration while compiled templates remain on disk. NVD status is Awaiting Analysis. CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to poc.

GitHub user murrez published a public Python repository for CVE-2026-82531. The README describes a warm → clear-cache → poison → trigger chain against applications using extends inheritance and template caching, and claims remote code execution verified with a response marker. ThreatWire did not run it. The publisher’s account hosts many recent CVE-titled exploit repositories, which is a packaging red flag but does not by itself disprove that this repo’s prose matches GHSA-3w63-v7pm-cq9x. Availability is therefore PoC. This record does not reprint markers, payloads, or exploit commands.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-82531