PortSwigger Web Security Academy: escaping a sandboxed FreeMarker engine by walking Java reflection from a user-supplied object all the way to an arbitrary file read.
Server-Side Template Injection in a Sandboxed Environment


PortSwigger Web Security Academy: escaping a sandboxed FreeMarker engine by walking Java reflection from a user-supplied object all the way to an arbitrary file read.

PortSwigger Web Security Academy: leaking Django’s SECRET_KEY through SSTI by using the {% debug %} tag and a reachable settings object, no code execution required.

PortSwigger Web Security Academy: fingerprinting Twig from errors, reading the app’s own source through an exposed object, and chaining its methods into a custom exploit that reads and deletes files.

PortSwigger Web Security Academy: server-side template injection in a code context, breaking out of a Tornado expression to reach command execution.

PortSwigger Web Security Academy: forcing an error to reveal Handlebars on Node.js, then adapting a documented exploit to reach remote code execution.