Code Injection Vulnerability in Smarty by Smarty
CVE-2026-82531
9.2CRITICAL
What is CVE-2026-82531?
Smarty prior to version 4.5.8 and 5.x before 5.8.5 has a code injection vulnerability that arises due to improper handling of the nocache_hash during template inheritance. This oversight allows attackers to introduce malicious code through crafted assigned data containing a forged SmartyNocache marker. When the PHP cache file is regenerated, this marker is executed without validation, leading to potential remote code execution risks. Users of affected Smarty versions are encouraged to update to the latest releases to mitigate this vulnerability.
Affected Version(s)
smarty 0 < 4.5.8
smarty 5.0.0 < 5.8.5
smarty 4.5.8
