Skip to content
Threat Feed
high advisory PoC updated

Smarty Template Inheritance Code Injection Vulnerability

Smarty versions before 4.5.8 and 5.8.5 are susceptible to code injection via template inheritance due to improper management of the nocache_hash variable, enabling unauthenticated remote code execution.

CVE search metadata

CVE search record: CVE-2026-82531. Severity: high. CVSS: 8.1. KEV: no. Product: Smarty (< 4.5.8, 5.x < 5.8.5), Smarty (< 4.5.8), Smarty (5.0.0 – 5.8.4). Brief: Smarty Template Inheritance Code Injection Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-10-smarty-rce/

What's new

  • 1. poc_available Oct 7, 06:38 via sploitus

Smarty versions 4.x before 4.5.8 and 5.x before 5.8.5 contain a critical code injection vulnerability caused by the improper restoration of the top-level nocache_hash during template inheritance processing. When using the extends:/multi-component template inheritance feature, the hash value is left as null. An attacker can supply crafted input containing a forged SmartyNocache marker as assigned data to the template engine. Because the engine fails to properly sanitize or scope this data during the cache regeneration process, the forged marker is written verbatim into the compiled PHP cache file. Subsequent requests that trigger the inclusion of this cached file cause the injected PHP payload to be executed on the server, resulting in arbitrary remote code execution (RCE). This vulnerability is particularly dangerous in web applications that allow user-controllable input to influence template variables.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary PHP code on the underlying web server. This can lead to full application compromise, data exfiltration, or the establishment of persistent backdoors within the web environment. The vulnerability impacts any application utilizing the affected Smarty template inheritance mechanism and exposed via user-supplied template data.

Recommendation

Prioritize the immediate remediation of vulnerable Smarty installations by upgrading to the patched versions.

  • Upgrade Smarty 4.x installations to version 4.5.8 or later.
  • Upgrade Smarty 5.x installations to version 5.8.5 or later.
  • Audit existing Smarty template implementations to ensure that user-supplied data is strictly sanitized before being assigned to templates, limiting the attacker's ability to inject payloads into the template engine.
  • Monitor web server error and access logs for unusual PHP execution patterns originating from cached template files or unexpected write operations to the template cache directory.

Immediate actions

Patch Smarty to 4.5.8 or 5.8.5

IT Operations 48h

Mitigations

Upgrade to Smarty 4.5.8 or 5.8.5

immediate IT Operations

CVE-2026-82531