<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>appsec.fyi — Server-Side Template Injection (SSTI)</title>
  <link>https://appsec.fyi/ssti.html</link>
  <description>Curated Server-Side Template Injection (SSTI) resources from appsec.fyi</description>
  <language>en-us</language>
  <atom:link href="https://appsec.fyi/feeds/ssti.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Fri, 10 Apr 2026 21:32:17 +0000</lastBuildDate>
  <managingEditor>carl@chs.us (Carl Sampson)</managingEditor>
  <item>
    <title>GoSecure: Template Injection in Action workshop</title>
    <link>https://gosecure.github.io/template-injection-workshop/</link>
    <guid isPermaLink="true">https://gosecure.github.io/template-injection-workshop/</guid>
    <description>GoSecure: Template Injection in Action workshop</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:22:07 +0000</pubDate>
  </item>
  <item>
    <title>Jinja2 SSTI filter bypasses</title>
    <link>https://medium.com/@nyomanpradipta120/jinja2-ssti-filter-bypasses-a8d3eb7b000f</link>
    <guid isPermaLink="true">https://medium.com/@nyomanpradipta120/jinja2-ssti-filter-bypasses-a8d3eb7b000f</guid>
    <description>Jinja2 SSTI filter bypasses</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:22:06 +0000</pubDate>
  </item>
  <item>
    <title>OnSecurity: Server Side Template Injection with Jinja2</title>
    <link>https://onsecurity.io/article/server-side-template-injection-with-jinja2/</link>
    <guid isPermaLink="true">https://onsecurity.io/article/server-side-template-injection-with-jinja2/</guid>
    <description>OnSecurity: Server Side Template Injection with Jinja2</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:22:06 +0000</pubDate>
  </item>
  <item>
    <title>Flask &amp; Jinja2 SSTI cheatsheet</title>
    <link>https://pequalsnp-team.github.io/cheatsheet/flask-jinja2-ssti</link>
    <guid isPermaLink="true">https://pequalsnp-team.github.io/cheatsheet/flask-jinja2-ssti</guid>
    <description>Flask &amp; Jinja2 SSTI cheatsheet</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:22:05 +0000</pubDate>
  </item>
  <item>
    <title>Grav: SSTI via Twig escape handler advisory</title>
    <link>https://github.com/getgrav/grav/security/advisories/GHSA-2m7x-c7px-hp58</link>
    <guid isPermaLink="true">https://github.com/getgrav/grav/security/advisories/GHSA-2m7x-c7px-hp58</guid>
    <description>Grav: SSTI via Twig escape handler advisory</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:22:04 +0000</pubDate>
  </item>
  <item>
    <title>Exploit-DB: Twig 2.4.4 Server Side Template Injection</title>
    <link>https://www.exploit-db.com/exploits/44102</link>
    <guid isPermaLink="true">https://www.exploit-db.com/exploits/44102</guid>
    <description>Exploit-DB: Twig 2.4.4 Server Side Template Injection</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:22:03 +0000</pubDate>
  </item>
  <item>
    <title>OpenMetadata: FreeMarker SSTI in email templates leads to RCE</title>
    <link>https://github.com/open-metadata/OpenMetadata/security/advisories/GHSA-5f29-2333-h9c7</link>
    <guid isPermaLink="true">https://github.com/open-metadata/OpenMetadata/security/advisories/GHSA-5f29-2333-h9c7</guid>
    <description>OpenMetadata: FreeMarker SSTI in email templates leads to RCE</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:22:02 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2023-49964: FreeMarker SSTI in Alfresco</title>
    <link>https://github.com/mbadanoiu/CVE-2023-49964</link>
    <guid isPermaLink="true">https://github.com/mbadanoiu/CVE-2023-49964</guid>
    <description>CVE-2023-49964: FreeMarker SSTI in Alfresco</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:22:02 +0000</pubDate>
  </item>
  <item>
    <title>GitHub Security Lab: SSTI in Apache Camel — CVE-2020-11994</title>
    <link>https://securitylab.github.com/advisories/GHSL-2020-086-087-088-089-apache-camel/</link>
    <guid isPermaLink="true">https://securitylab.github.com/advisories/GHSL-2020-086-087-088-089-apache-camel/</guid>
    <description>GitHub Security Lab: SSTI in Apache Camel — CVE-2020-11994</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:22:01 +0000</pubDate>
  </item>
  <item>
    <title>Breaking the Barrier: RCE via SSTI in FreeMarker</title>
    <link>https://medium.com/@armaanpathan/breaking-the-barrier-remote-code-execution-via-ssti-in-freemarker-template-engine-9797079752ac</link>
    <guid isPermaLink="true">https://medium.com/@armaanpathan/breaking-the-barrier-remote-code-execution-via-ssti-in-freemarker-template-engine-9797079752ac</guid>
    <description>Breaking the Barrier: RCE via SSTI in FreeMarker</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:22:00 +0000</pubDate>
  </item>
  <item>
    <title>Synack: Discovering an SSTI vulnerability in FreeMarker</title>
    <link>https://www.synack.com/exploits-explained/exploits-explained-discovering-a-server-side-template-injection-vuln-in-freemarker/</link>
    <guid isPermaLink="true">https://www.synack.com/exploits-explained/exploits-explained-discovering-a-server-side-template-injection-vuln-in-freemarker/</guid>
    <description>Synack: Discovering an SSTI vulnerability in FreeMarker</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:22:00 +0000</pubDate>
  </item>
  <item>
    <title>YesWeHack: Limitations are just an illusion — advanced SSTI exploitation with RCE everywhere</title>
    <link>https://www.yeswehack.com/learn-bug-bounty/server-side-template-injection-exploitation</link>
    <guid isPermaLink="true">https://www.yeswehack.com/learn-bug-bounty/server-side-template-injection-exploitation</guid>
    <description>YesWeHack: Limitations are just an illusion — advanced SSTI exploitation with RCE everywhere</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:58 +0000</pubDate>
  </item>
  <item>
    <title>vladko312/SSTImap: Automatic SSTI detection tool with interactive interface</title>
    <link>https://github.com/vladko312/SSTImap</link>
    <guid isPermaLink="true">https://github.com/vladko312/SSTImap</guid>
    <description>vladko312/SSTImap: Automatic SSTI detection tool with interactive interface</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:57 +0000</pubDate>
  </item>
  <item>
    <title>epinna/tplmap: SSTI and Code Injection Detection and Exploitation Tool</title>
    <link>https://github.com/epinna/tplmap</link>
    <guid isPermaLink="true">https://github.com/epinna/tplmap</guid>
    <description>epinna/tplmap: SSTI and Code Injection Detection and Exploitation Tool</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:56 +0000</pubDate>
  </item>
  <item>
    <title>PayloadsAllTheThings SSTI: Java</title>
    <link>https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Server%20Side%20Template%20Injection/Java.md</link>
    <guid isPermaLink="true">https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Server%20Side%20Template%20Injection/Java.md</guid>
    <description>PayloadsAllTheThings SSTI: Java</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:55 +0000</pubDate>
  </item>
  <item>
    <title>PayloadsAllTheThings: Server Side Template Injection</title>
    <link>https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Template%20Injection</link>
    <guid isPermaLink="true">https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Template%20Injection</guid>
    <description>PayloadsAllTheThings: Server Side Template Injection</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:54 +0000</pubDate>
  </item>
  <item>
    <title>HackTricks: Jinja2 SSTI</title>
    <link>https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti</link>
    <guid isPermaLink="true">https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti</guid>
    <description>HackTricks: Jinja2 SSTI</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:53 +0000</pubDate>
  </item>
  <item>
    <title>HackTricks: SSTI (Server Side Template Injection)</title>
    <link>https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection</link>
    <guid isPermaLink="true">https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection</guid>
    <description>HackTricks: SSTI (Server Side Template Injection)</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:52 +0000</pubDate>
  </item>
  <item>
    <title>OWASP Testing for Server Side Template Injection</title>
    <link>https://owasp.org/www-project-web-security-testing-guide/v41/4-Web_Application_Security_Testing/07-Input_Validation_Testing/18-Testing_for_Server_Side_Template_Injection</link>
    <guid isPermaLink="true">https://owasp.org/www-project-web-security-testing-guide/v41/4-Web_Application_Security_Testing/07-Input_Validation_Testing/18-Testing_for_Server_Side_Template_Injection</guid>
    <description>OWASP Testing for Server Side Template Injection</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:52 +0000</pubDate>
  </item>
  <item>
    <title>Server-side template injection PortSwigger KB</title>
    <link>https://portswigger.net/kb/issues/00101080_server-side-template-injection</link>
    <guid isPermaLink="true">https://portswigger.net/kb/issues/00101080_server-side-template-injection</guid>
    <description>Server-side template injection PortSwigger KB</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:51 +0000</pubDate>
  </item>
  <item>
    <title>Exploiting server-side template injection vulnerabilities</title>
    <link>https://portswigger.net/web-security/server-side-template-injection/exploiting</link>
    <guid isPermaLink="true">https://portswigger.net/web-security/server-side-template-injection/exploiting</guid>
    <description>Exploiting server-side template injection vulnerabilities</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:50 +0000</pubDate>
  </item>
  <item>
    <title>Template Injection Research | PortSwigger Research</title>
    <link>https://portswigger.net/research/template-injection</link>
    <guid isPermaLink="true">https://portswigger.net/research/template-injection</guid>
    <description>Template Injection Research | PortSwigger Research</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:49 +0000</pubDate>
  </item>
  <item>
    <title>Server-Side Template Injection | PortSwigger Research</title>
    <link>https://portswigger.net/research/server-side-template-injection</link>
    <guid isPermaLink="true">https://portswigger.net/research/server-side-template-injection</guid>
    <description>Server-Side Template Injection | PortSwigger Research</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:48 +0000</pubDate>
  </item>
  <item>
    <title>Server-side template injection | Web Security Academy</title>
    <link>https://portswigger.net/web-security/server-side-template-injection</link>
    <guid isPermaLink="true">https://portswigger.net/web-security/server-side-template-injection</guid>
    <description>Server-side template injection | Web Security Academy</description>
    <category>Server-Side Template Injection (SSTI)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:48 +0000</pubDate>
  </item>
</channel>
</rss>