appsec.fyi

SSTI — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

SSTI: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 98 of 98 curated resources. Browse all 98 SSTI resources →

Problem Framing

Server-Side Template Injection (SSTI) is a critical web application vulnerability that arises when an attacker can inject malicious code into a server-side template. This code is then processed and executed by the template engine on the server, potentially leading to remote code execution (RCE), information disclosure, denial-of-service, or other severe security compromises [1][2][3][4][5][6][7][8][9][10].

Unlike client-side injection vulnerabilities like Cross-Site Scripting (XSS), which target the user's browser, SSTI directly attacks the server itself. The impact can be profound, granting attackers a foothold within the application's environment, access to sensitive data, and the ability to compromise the entire system [2][3][4].

Template engines are fundamental to modern web development, separating presentation logic from application code and enabling dynamic content generation. While beneficial, their inherent ability to execute code makes them a prime target for attackers if user input is not handled with extreme care [2][3]. The vulnerability typically occurs when user-controlled data is directly concatenated into a template string or used as part of a template expression without proper sanitization, validation, or escaping [1][2][4][6].

Core Mechanics

At its heart, SSTI exploits the feature of template engines that allows them to evaluate expressions and execute code within their processing context. The vulnerability manifests when an application fails to distinguish between literal data and executable template code, particularly when this code originates from user input.

Template engines use specific syntax to denote placeholders, variables, and control structures. Common examples include double curly braces {{ ... }} (Jinja2, Twig), ${ ... } (FreeMarker, Velocity), and <%= ... %> (ERB) [2][4][6][10]. When an application incorrectly allows user-supplied input to be interpreted as part of this template syntax, an attacker can inject directives that the template engine will execute server-side.

The basic exploitation pattern involves:

1. Identifying Input Vectors: Locating any user-controllable input points within the application (e.g., URL parameters, form fields, HTTP headers, cookies) that are likely to be processed by a server-side template engine [11][5][10]. 2. Probing for Template Evaluation: Injecting basic template syntax, often simple mathematical expressions like {{77}} or ${77}, to observe if the server evaluates and renders the result (e.g., 49) instead of displaying the literal expression [2][4][5][6][10]. 3. Identifying the Template Engine: Different template engines use distinct syntaxes and have unique features. Detecting the specific engine in use is crucial for crafting targeted payloads. Error messages, successful evaluation of specific syntaxes, or the use of fingerprinting tools can aid in this identification [2][11][10]. 4. Escalating to Code Execution: Once template evaluation is confirmed, the attacker attempts to leverage the engine's capabilities to access internal objects, methods, or functions that allow arbitrary code execution or file system access [2][4][5][10].

The core of the vulnerability lies in the dynamic construction of templates from user input. A safe practice involves passing user input as data variables to a predefined template, rather than directly embedding it into the template string itself [1][2][12][13][14][10].

Notable Techniques

The exploitation of SSTI vulnerabilities is highly dependent on the specific template engine and the context in which it is used. However, several common techniques and payload patterns have emerged.

Detection Payloads

The initial step in identifying an SSTI vulnerability is to use basic template syntax that demonstrates server-side evaluation.

Exploitation Payloads & Techniques

Once a vulnerability is confirmed, attackers aim to leverage it for RCE or sensitive data access. The specific payloads depend heavily on the template engine and available objects/functions.

Detection & Prevention

Effective detection and prevention of SSTI vulnerabilities require a multi-layered approach focusing on secure coding practices and vigilant monitoring.

Detection

Prevention

Tooling

Several tools exist to aid in the detection and exploitation of SSTI vulnerabilities.

Recent Developments

The landscape of SSTI vulnerabilities continues to evolve, with new techniques and targets emerging regularly.

Where to Go Deeper

For practitioners seeking to deepen their understanding of SSTI, the following resources offer valuable insights and practical guidance:

Sources cited in this guide

  1. SSTI: Explanation, Discovery, Exploitation, and Prevention — akto.io
  2. SSTI: Breaking Out of Templates — kayssel.com
  3. A Survey of the Overlooked Dangers of Template Engines (arXiv 2024) — arxiv.org
  4. Inj3ctlab — SSTI Bug Bounty Labs Writeup — len4m.github.io
  5. Find and Exploit Server-Side Template Injection — TCM Security — tcm-sec.com
  6. What is Server-Side Template Injection? (Indusface) — indusface.com
  7. A Pentester's Guide to SSTI - Cobalt — cobalt.io
  8. SSTI: Transforming Web Apps from Assets to Liabilities — research.checkpoint.com
  9. Server-side template injection PortSwigger KB — portswigger.net
  10. Server-Side Template Injection | PortSwigger Research — portswigger.net
  11. PayloadsAllTheThings — SSTI README — github.com
  12. Practical Exploitation of SSTI in Flask with Jinja2 — karczewski.io
  13. SSTI Explained with Real Code Examples - Xygeni — xygeni.io
  14. vladko312/SSTImap: Automatic SSTI detection tool with interactive interface — github.com
  15. SSTI: Advanced Exploitation Guide - Intigriti — intigriti.com
  16. Flask & Jinja2 SSTI cheatsheet — pequalsnp-team.github.io
  17. OWASP Testing for Server Side Template Injection — owasp.org
  18. Exploiting SSTI in Thymeleaf — acunetix.com
  19. PayloadsAllTheThings SSTI: Java — github.com
  20. Server Side Template Injection - Payloads All The Things — swisskyrepo.github.io
  21. What is SSTI in Flask/Jinja2? — Payatu — payatu.com
  22. A Simple Flask (Jinja2) SSTI Example (Kleiber) — kleiber.me
  23. HackTricks: Jinja2 SSTI — book.hacktricks.xyz
  24. SSTI (The Hacker Recipes) — thehacker.recipes
  25. SSTI in Jinja2 allows RCE (changedetection.io) — github.com
  26. Jinja2 template injection filter bypasses (0day.work) — 0day.work
  27. Jinja2/Flask SSTI Filter bypass (MRLSECURITY) — mrlsecurity.com
  28. Jinja2 SSTI filter bypasses — medium.com
  29. YesWeHack: Limitations are just an illusion — advanced SSTI exploitation with RCE everywhere — yeswehack.com
  30. Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE — rapid7.com
  31. Grav CMS: RCE via SSTI through Twig Sandbox Bypass — github.com
  32. Exploit-DB: Twig 2.4.4 Server Side Template Injection — exploit-db.com
  33. Exploiting CVE-2021-25770: SSTI in YouTrack (Synacktiv) — synacktiv.com
  34. CVE-2024-29178: Apache StreamPark FreeMarker SSTI — openwall.com
  35. Breaking the Barrier: RCE via SSTI in FreeMarker — medium.com
  36. Synack: Discovering an SSTI vulnerability in FreeMarker — synack.com
  37. Ruby ERB Template Injection (TrustedSec) — trustedsec.com
  38. PayloadsAllTheThings: SSTI Ruby payloads — github.com
  39. ruby-ssti: example Ruby ERB app vulnerable to SSTI — github.com
  40. Exploiting server-side template injection vulnerabilities — portswigger.net
  41. Code Execution via Text Template Files | Playbook & Detection — ipurple.team
  42. ServiceNow RCE Exploitation Campaign — resecurity.com
  43. ServiceNow RCE (CVE-2024-4879) Analysis — cyfirma.com
  44. Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) — snyk.io
  45. CVE-2026-27641: Flask-Reuploaded Path Traversal Enabling SSTI RCE — github.com
  46. Grav CMS: Security Sandbox Bypass with SSTI — github.com
  47. Grav: SSTI via Twig escape handler advisory — github.com
  48. CVE-2021-43466: Thymeleaf Spring5 RCE — security.snyk.io
  49. CVE-2025-23211: Tandoor Recipes Jinja2 SSTI to RCE — offsec.com
  50. Handlebars.js: Safe Usage to Avoid Injection Flaws — xygeni.io
  51. epinna/tplmap: SSTI and Code Injection Detection and Exploitation Tool — github.com
  52. PayloadsAllTheThings: Server Side Template Injection — github.com
  53. GoSecure: Template Injection in Action workshop — gosecure.github.io
  54. SSTI in Flask/Jinja2 (IndominusByte) — medium.com
  55. SpringBootAdmin Thymeleaf SSTI to RCE — github.com
  56. CVE-2022-46166: Spring Boot Admin RCE — sangfor.com
  57. GitHub Security Lab: SSTI in Apache Camel — CVE-2020-11994 — securitylab.github.com
  58. OpenMetadata: FreeMarker SSTI in email templates leads to RCE — github.com
  59. CVE-2025-23211: Jinja2 SSTI Turns Recipes Into RCE — vsec.com.br
  60. Multiple ServiceNow SSTI Vulnerabilities — censys.com
  61. AST Injection: Prototype Pollution to RCE in Handlebars — po6ix.github.io
  62. Method Confusion in Go SSTIs Lead to RCE — onsecurity.io
  63. Exploiting SSTI in Golang Frameworks — payatu.com
  64. Golang SSTI: Safe by Default or Vulnerable by Design — oligo.security
  65. Server-side template injection | Web Security Academy — portswigger.net
  66. HackTricks: SSTI (Server Side Template Injection) — book.hacktricks.xyz
  67. PayloadsAllTheThings - SSTI JavaScript engines — github.com
  68. Bug Bytes #124: SSTI to RCE in Go apps (Intigriti) — blog.intigriti.com
  69. Mastering SSTI Exploitation: Executing Commands in Popular Templating Engines — medium.com
  70. SSTI: Advanced Exploitation Techniques (BootstrapSecurity) — medium.com
  71. SSTI - Server-side template injection with a custom exploit (Scott Murray) — sc.scomurr.com
  72. Deep Dive into SSTI: Finding and Exploiting Like a Pro — infosecwriteups.com
  73. Handlebars template injection and RCE in Shopify app — mahmoudsec.blogspot.com
  74. Exploiting Jinja SSTI with limited payload size — niebardzo.github.io
  75. RCE via SSTI in Fides Jinja Email Templates — github.com
  76. Exploiting SSTI in a Modern Spring Boot Application — modzero.com
  77. OnSecurity: Server Side Template Injection with Jinja2 — onsecurity.io
  78. CVE-2023-49964: FreeMarker SSTI in Alfresco — github.com
  79. Metasploit Module: Tactical RMM Jinja2 SSTI RCE (CVE-2025-69516) — github.com
  80. Atlassian Confluence Widget Connector Macro SSTI (ExploitDB) — exploit-db.com
  81. Setting Up a Vulnerable SSTI Lab: A Hands-On Guide — medium.com
  82. picoCTF 2025: SSTI2 Exploitation Writeup — medium.com
  83. picoCTF 2025: SSTI Challenge Writeup — medium.com
📚 This guide is synthesized from the full text of resources curated in the SSTI library, and refreshed as new material is added.