CVE-2026-82531: Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inheritance Cache
Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocachehash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution.
Affected Software
Event History
Frequently Asked Questions
Which Smarty versions need to be remediated?
Smarty versions before 4.5.8 are affected, as are 5.x versions before 5.8.5. Upgrade to 4.5.8 or later in the 4.x line, or to 5.8.5 or later in the 5.x line.
What conditions are required for exploitation?
An attacker must be able to supply assigned template data containing a forged SmartyNocache marker. Exploitation also relies on extends: or multi-component template inheritance causing regeneration of a PHP cache file that is later included.
What is the impact if exploitation succeeds?
The forged marker can be copied verbatim into a regenerated PHP cache file. When that file is included, the injected PHP executes, resulting in remote code execution with the privileges of the PHP process.