Smarty Cache Poisoning RCE (CVE-2026-82531): SmartyNocache and extends Templates
Admin · October 9, 2026 · 9 views
Smarty cache files are PHP on disk
CVE-2026-82531 hits the Smarty PHP template engine used inside CMS themes, shops, and custom apps—not a WordPress plugin headline, but the same CWE-94 class outcome: code in generated cache PHP executed on include().
Affected: < 4.5.8 and 5.0.0 – 5.8.4. Fixed: 4.5.8, 5.8.5. CVSS 4.0 9.2 Critical with AT:P—caching on, extends: inheritance, user-influenced assign(), and a cache miss while compiled templates remain warm.
PoC and Docker lab: CVE-2026-82531 on pocbit.org. Repository: murrez/CVE-2026-82531. Advisory: GHSA-3w63-v7pm-cq9x.
Mechanism (short)
When nocache_hash is null after workers reload compiled templates, cache regeneration builds a regex with an empty alternative. Attacker-controlled assign data can forge:
/*%%SmartyNocache:%%*/ <?php ... ?> /*/%%SmartyNocache:%%*/
That block lands verbatim in the cache PHP file; the next request that includes the cache runs attacker PHP. Verify marker: POCBIT-82531-OK.
Defender checklist
| # | Action | Detail |
|---|--------|--------|
| 1 | Composer audit | smarty/smarty version in every PHP app you ship |
| 2 | Upgrade to ≥ 4.5.8 or ≥ 5.8.5 | Lockfile + deploy, not manual vendor copy |
| 3 | After patch | Delete all template cache directories—not only compiled templates |
| 4 | App review | Where do visitors influence assign() on extends layouts? |
| 5 | Lab only | PoC warm → clear cache → poison → trigger chain |
Cross-read: RCE vs local privilege escalation, file upload / write vulnerabilities (cache-as-write primitive).
Patch validation
Use the public bundle cve-2026-82531.py, docker compose up, Smarty 5.8.4 lab, then python poc.py exploit. After upgrade to 5.8.5, repeat—expect failure. See safe PoC lab setup.
FAQ
We do not expose Smarty to users—safe?
If any request path feeds user text into assign() on cached extends templates, revisit AT:P assumptions.
Is this Symfony/Laravel core?
Smarty library—inventory Composer, not only framework CVE feeds.
Bottom line
CVE-2026-82531 is cache poisoning → RCE in a legacy-but-ubiquitous engine. Patch Smarty, flush caches, and map assign() trust boundaries in PHP apps you operate.