Skip to content
THREATWIRE

News

Smarty cache injection is CVE-2026-82531

GHSA-3w63-v7pm-cq9x / CVE-2026-82531: Smarty before 4.5.8 and 5.x before 5.8.5 can write forged SmartyNocache content from assigned data into regenerated PHP caches during extends inheritance, enabling RCE on include. CVSS 4.0 9.2. Public PoC exists. Fixed in 4.5.8 and 5.8.5. Not in CISA KEV.

Critical

Published 7 Oct 2026

PoC link

On this page

What happened

On 4 October 2026 the Smarty project published GitHub Security Advisory GHSA-3w63-v7pm-cq9x. The issue was recorded as CVE-2026-82531 (VulnCheck CNA) on 6 October 2026. In Smarty’s extends: / multi-component inheritance compile path, the top-level nocache_hash is never restored and stays null. During cache regeneration, that null hash produces an empty alternative in the nocache-marker regex, so assigned data can forge a SmartyNocache wrapper. Marker-wrapped content is copied verbatim into the generated PHP cache file and executes on the next include—CWE-94 code injection leading to remote code execution.

Who is affected

Applications using Composer package smarty/smarty before 4.5.8, or on the 5.x line from 5.0.0 through versions before 5.8.5, are in scope when caching is enabled, inheritance templates are used, escape_html remains off (the default), and attacker-influenced values reach an unescaped assign/echo path with a later cache regeneration. Sites that never enable Smarty caching or never use extends inheritance are outside the advisory’s confirmed preconditions.

What is confirmed

GHSA-3w63-v7pm-cq9x documents the missing hash restoration, the empty-regex alternative, verbatim cache writes, and end-to-end local confirmation of attacker-supplied PHP execution. Fixed versions are 4.5.8 and 5.8.5. VulnCheck publishes CVSS 4.0 9.2 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N) and CVSS 3.1 8.1. NVD status is Awaiting Analysis. CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to poc.

GitHub user murrez published a public repository for CVE-2026-82531. The README describes a Python PoC that claims to warm templates, clear cache, poison assigned name data with a forged SmartyNocache block, then trigger cache include for remote code execution, reporting a verification marker in the HTTP body. ThreatWire did not run the project. Availability is therefore PoC.

What is not confirmed

Exploitation in the wild is not confirmed by Smarty or CISA. The murrez account publishes many CVE-titled exploit repositories in rapid succession; that pattern is a packaging red flag and is why ThreatWire treats the README’s claimed RCE result as an unverified claim about a matching public PoC, not as evidence of mass campaigns. ThreatWire did not verify the Docker lab or poc.py beyond public metadata and prose.

What to do

Upgrade Smarty to 4.5.8 or 5.8.5 (or later). After upgrading, delete or regenerate all template cache files so poisoned caches cannot keep executing. Review where request or user data is passed to assign() and prefer enabling HTML escaping where appropriate. Inventory Composer lockfiles for smarty/smarty across applications, not only front-door CMS packages.

Sources: GHSA-3w63-v7pm-cq9x, Smarty v4.5.8 and v5.8.5 releases, NVD and CVE.org for CVE-2026-82531, and the public PoC repository metadata.

Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/news/smarty-cache-injection-is-cve-2026-82531

More articles