SSTI
appsec.fyi
Code Execution via Text Template Files | Playbook & Detection
2026-08-25
Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478)
2026-06-08
SSTI in Bug Bounty: Playing with Handlebars and Breaking Stuff
2026-04-22
SSTI: Explanation, Discovery, Exploitation, and Prevention
2026-04-22
SSTI: Breaking Out of Templates
2026-04-22
More SSTI →