Open cardosec

Case 3EB819 · Web AppSec · L4 Advanced

Server-Side Template Injection

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. SSTI occurs when user input becomes part of a template source rather than data passed into the template
  2. Detection: polyglot probes like {{7*7}} or ${7*7} returning 49 and error messages fingerprint the engine
  3. Jinja2 escalation walks the object graph (__class__.__mro__, __subclasses__) to reach os or subprocess
  4. Impact is usually full RCE as the app user, unlike XSS which is client-side only
  5. Fix: never build templates from input, pass it as context; prefer logic-less engines, as sandboxes have been escaped

If the interviewer pushes back

  • How would you distinguish SSTI from reflected XSS when {{7*7}} is echoed back unchanged?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.