{"id":"CVE-2026-82531","title":"Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null","summary":"Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94"],"vendor":"smarty-php","product":"smarty","affected":["smarty < 4.5.8","smarty >= 5.0.0 < 5.8.5"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T16:00:36.547","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82531","references":[{"url":"https://github.com/smarty-php/smarty/commit/1cba51cb813563eb61d963c83d28cd59f26b858d","label":"disclosure@vulncheck.com"},{"url":"https://github.com/smarty-php/smarty/commit/c0fdd4824aca4f67e814b50703cfee1dfde41414","label":"disclosure@vulncheck.com"},{"url":"https://github.com/smarty-php/smarty/releases/tag/v4.5.8","label":"disclosure@vulncheck.com"},{"url":"https://github.com/smarty-php/smarty/releases/tag/v5.8.5","label":"disclosure@vulncheck.com"},{"url":"https://github.com/smarty-php/smarty/security/advisories/GHSA-3w63-v7pm-cq9x","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/smarty-before-4.5.8-and-5-x-before-5.8.5-php-code-injection-via-extends-inheritance-cache","label":"disclosure@vulncheck.com"},{"url":"https://github.com/smarty-php/smarty/security/advisories/GHSA-3w63-v7pm-cq9x","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-10-06T12:44:36.819504Z"},"ingestedAt":"2026-10-06T12:59:11.019Z","slug":"CVE-2026-82531","body":"## Overview\n\nSmarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}