CVE-2026-82531

Summary

Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution.

Affected Software

VendorProductVersion RangeStatus
smarty-phpsmarty0 < 4.5.8affected
smarty-phpsmarty5.0.0 < 5.8.5affected
smarty-phpsmarty4.5.8unaffected
smarty-phpsmarty5.8.5unaffected

Weaknesses

  • CWE-94: Improper Control of Generation of Code ('Code Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: total

Additional References

References