{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/smarty--4.5.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:smarty:smarty:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-82531"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=0D71BB83-F55B-5D6D-B9DD-846D59C52489\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Smarty (\u003c 4.5.8, 5.x \u003c 5.8.5)","Smarty (\u003c 4.5.8)","Smarty (5.0.0 – 5.8.4)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","vulnerability","php"],"_cs_type":"advisory","_cs_vendors":["Smarty"],"content_html":"\u003cp\u003eSmarty versions 4.x before 4.5.8 and 5.x before 5.8.5 contain a critical code injection vulnerability caused by the improper restoration of the top-level nocache_hash during template inheritance processing. When using the extends:/multi-component template inheritance feature, the hash value is left as null. An attacker can supply crafted input containing a forged SmartyNocache marker as assigned data to the template engine. Because the engine fails to properly sanitize or scope this data during the cache regeneration process, the forged marker is written verbatim into the compiled PHP cache file. Subsequent requests that trigger the inclusion of this cached file cause the injected PHP payload to be executed on the server, resulting in arbitrary remote code execution (RCE). This vulnerability is particularly dangerous in web applications that allow user-controllable input to influence template variables.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary PHP code on the underlying web server. This can lead to full application compromise, data exfiltration, or the establishment of persistent backdoors within the web environment. The vulnerability impacts any application utilizing the affected Smarty template inheritance mechanism and exposed via user-supplied template data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate remediation of vulnerable Smarty installations by upgrading to the patched versions.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Smarty 4.x installations to version 4.5.8 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade Smarty 5.x installations to version 5.8.5 or later.\u003c/li\u003e\n\u003cli\u003eAudit existing Smarty template implementations to ensure that user-supplied data is strictly sanitized before being assigned to templates, limiting the attacker's ability to inject payloads into the template engine.\u003c/li\u003e\n\u003cli\u003eMonitor web server error and access logs for unusual PHP execution patterns originating from cached template files or unexpected write operations to the template cache directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T06:38:00Z","date_published":"2026-10-06T14:55:49Z","id":"https://feed.craftedsignal.io/briefs/2026-10-smarty-rce/","summary":"Smarty versions before 4.5.8 and 5.8.5 are susceptible to code injection via template inheritance due to improper management of the nocache_hash variable, enabling unauthenticated remote code execution.","title":"Smarty Template Inheritance Code Injection Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-10-smarty-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Smarty (\u003c 4.5.8)","version":"https://jsonfeed.org/version/1.1"}