POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Web appcritical

CVE-2026-82531 — Smarty Template Cache Poisoning RCE (SmartyNocache / extends)

October 7, 2026 · 71 views

smarty-php/smarty <4.5.8 and 5.0.0–5.8.4: extends/inheritance + cache regen with null nocache_hash lets forged assign() data inject SmartyNocache markers into cache PHP → include() RCE. CWE-94, CVSS 4.0 9.2 Critical (AT:P). Fixed 4.5.8 / 5.8.5. Python PoC: check/exploit/payload, Docker lab 5.8.4, hits.txt & exploited.txt. Marker POCBIT-82531-OK.

#smarty#php#template-engine#cache-poisoning#code-injection#cwe-94#rce#critical

CVE:

CVE-2026-82531

Date:

2026-10-07

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-82531 — Smarty PHP template engine (smarty-php/smarty) — code injection (CWE-94) via forged SmartyNocache markers in template cache files when using extends: / block inheritance.

| | | |---|---| | Affected | < 4.5.8; 5.0.0 – 5.8.4 | | Fixed | 4.5.8, 5.8.5 | | CVSS 4.0 | 9.2 Critical — AT:P (caching + extends + user-controlled assign) | | CVSS 3.1 | 8.1 High | | Verify marker | POCBIT-82531-OK (base64 command output in body) |

After a PHP worker loads compiled templates from disk, nocache_hash can be null during cache regeneration. Smarty_Internal_Runtime_UpdateCache then builds a regex with an empty alternative, so attacker assign() data can forge /*%%SmartyNocache:%%*/ <?php ... ?> /*/%%SmartyNocache:%% into the cache PHP file. The next include() of that cache executes injected PHP.

PoC page: https://pocbit.org/pocs/cve-2026-82531

GitHub: murrez/CVE-2026-82531

CVE.org: CVE-2026-82531

GHSA: GHSA-3w63-v7pm-cq9x

Exploit chain (PoC exploit)

| Phase | Action | |-------|--------| | 1 Warm | Benign assign → compile + initial cache | | 2 Clear | Drop cache files (compiled templates remain); lab: ?lab_clear_cache=1 | | 3 Poison | name= forged SmartyNocache + shell_exec | | 4 Trigger | Benign request → include() runs PHP; body POCBIT-82531-OK: + base64 |

Production targets need caching on, extends templates, user-controlled assign, and a cache miss while compile dir is warm (TTL, restart, admin flush).

Bundled tool (Python 3 + Docker lab)

Download cve-2026-82531.py — extracts poc.py, requirements.txt, docker-compose.yml, and lab/ tree.

python cve-2026-82531.py
pip install -r requirements.txt

docker compose up --build -d
python poc.py check http://127.0.0.1:8088
python poc.py exploit --url http://127.0.0.1:8088 -c "id"
python poc.py exploit -i targets.example.txt -w 10 -c id
python poc.py payload -c "id"

After patching: delete/regenerate all template cache files.

Remediation

  1. Upgrade Smarty to ≥ 4.5.8 or ≥ 5.8.5 (Composer lockfile audit).
  2. Flush template cache after upgrade—not only compiled templates.
  3. Inventory apps embedding Smarty (CMS, shop themes, custom PHP).

Legal and ethical use

Authorized security testing only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →