8.1
CVE-2026-82531
- EPSS 0.82%
- Veröffentlicht 06.10.2026 12:18:31
- Zuletzt bearbeitet 06.10.2026 16:00:36
- Erkennungen
Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inheritance Cache
Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellersmarty-php
≫
Produkt
smarty
Default Statusunaffected
Version
0
Version <
4.5.8
Status
affected
Version
5.0.0
Version <
5.8.5
Status
affected
Version
4.5.8
Status
unaffected
Version
5.8.5
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.82% | 0.56 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| disclosure@vulncheck.com | 9.2 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
https://github.com/smarty-php/smarty/security/advisories/GHSA-3w63-v7pm-cq9x
https://github.com/smarty-php/smarty/commit/c0fdd4824aca4f67e814b50703cfee1dfde41414
https://github.com/smarty-php/smarty/commit/1cba51cb813563eb61d963c83d28cd59f26b858d
https://github.com/smarty-php/smarty/releases/tag/v5.8.5
https://github.com/smarty-php/smarty/releases/tag/v4.5.8
https://www.vulncheck.com/advisories/smarty-before-4.5.8-and-5-x-before-5.8.5-php-code-injection-via-extends-inheritance-cache