Skip to content
Threat Feed

Tag

Ssti

20 briefs RSS
high advisory

Second-Order SSTI in SiYuan via Attribute-View Template Columns

SiYuan kernel is vulnerable to a second-order SSTI via the queryBlocks template function, allowing attackers to achieve arbitrary SQL execution upon rendering imported malicious content.

kernel vulnerability ssti sql-injection rce
2t 1c
critical advisory

Critical RCE via Server-Side Template Injection in OpenSAGRES XDocReport

OpenSAGRES XDocReport is vulnerable to a critical server-side template injection (SSTI) flaw via the Apache Velocity engine, allowing unauthenticated remote code execution through malicious .docx uploads.

XDocReport +1 vulnerability rce ssti webserver
2t 1c
critical threat

Unauthenticated RCE via Server-Side Template Injection in Atlassian Jira

An unauthenticated remote code execution vulnerability (CVE-2019-11581) exists in the 'ContactAdministrators' form of Atlassian Jira Server due to insecure Velocity template rendering of the 'subject' parameter.

exploited Jira Server web-application-vulnerability rce ssti jira
1r 2t 1c
high advisory

Trestle Server-Side Template Injection via Custom Jinja2 Extensions

The Trestle command-line tool is vulnerable to Server-Side Template Injection (SSTI) due to the unsafe re-evaluation of untrusted Markdown content as Jinja2 template code.

trestle ssti rce python jinja2
1t
high advisory

Remote Code Execution via SSTI in mcp-contextforge-gateway

An authenticated Server-Side Template Injection (SSTI) vulnerability in mcp-contextforge-gateway version 0.9.0 and earlier allows attackers to achieve Remote Code Execution via unsandboxed Jinja2 template rendering.

mcp-contextforge-gateway ssti rce vulnerability
1r 1t
high advisory

Remote Code Execution in Grav CMS Flex Objects Plugin

Authenticated users can achieve remote code execution in Grav CMS versions prior to 2.0.13 by exploiting improper input validation in the Flex Objects plugin to upload and execute arbitrary PHP files.

Grav CMS +2 web-application-vulnerability rce ssti cms privilege-escalation web-application remote-code-execution cve-2026-75827
2r 6t 1c updated
high advisory

Authentication Scope Bypass in Grav API Plugin Leading to RCE

An API key scope-cap bypass in the Grav API plugin allows attackers with restricted keys to execute server-side templates via Server-Side Template Injection.

grav-plugin-api +2 web-vulnerability rce ssti grav-cms web-application-vulnerability cve-2026-75829
1r 3t 1c updated
high advisory

YesWiki Bazar Admin Server-Side Template Injection to RCE (CVE-2026-52762)

An authenticated administrator can exploit a Server-Side Template Injection (SSTI) vulnerability (CVE-2026-52762) in YesWiki Bazar's semantic templates to achieve Remote Code Execution (RCE) on the underlying server, allowing for full system compromise.

YesWiki 4.x yeswiki ssti rce web-application php cve
1r 3t
high advisory

Kirby CMS Server-Side Template Injection via Double Template Resolution

A server-side template injection (SSTI) vulnerability exists in Kirby CMS within the option rendering feature due to double template resolution in option fields (checkboxes, color, multiselect, select, radio, tags, or toggles) when using options from a query or API with untrusted values, potentially allowing attackers to inject malicious queries.

cms ssti kirby template-injection
2r 1t
critical advisory

BentoML SSTI via Unsandboxed Jinja2 in Dockerfile Generation

BentoML versions 1.4.37 and earlier are vulnerable to server-side template injection (SSTI), where the Dockerfile generation function uses an unsandboxed jinja2.Environment allowing arbitrary Python code execution on the host machine when a malicious bento archive is imported and containerized, bypassing container isolation and potentially granting full access to the host filesystem and environment variables.

ssti bentoml code-execution docker
2r 1t
critical advisory

Contact Form by Supsystic WordPress Plugin SSTI Vulnerability (CVE-2026-4257)

The Contact Form by Supsystic WordPress plugin is vulnerable to Server-Side Template Injection (SSTI) via the `cfsPreFill` parameter, leading to unauthenticated Remote Code Execution (RCE).

ssti wordpress rce twig
2r 1t 1c
critical advisory

Giskard-agents ChatWorkflow.chat() Server-Side Template Injection

Giskard-agents versions 0.3.3 and earlier, and versions 1.0.1a1 through 1.0.2a1 are vulnerable to remote code execution via server-side template injection where the ChatWorkflow.chat() method passes user-supplied strings directly to a non-sandboxed Jinja2 Environment, allowing attackers to execute arbitrary code on the server.

ssti jinja2 rce giskard-agents vulnerability
2r 1t
critical threat

CrushFTP Server-Side Template Injection Exploitation

Exploitation of CVE-2024-4040, a server-side template injection vulnerability in CrushFTP, allows unauthenticated remote attackers to access files, circumvent authentication, and execute arbitrary commands.

exploited CrushFTP Server crushftp ssti cve-2024-4040
2r 2t 1c
high advisory

LiteLLM Server-Side Template Injection Vulnerability

A server-side template injection vulnerability in LiteLLM versions 1.80.5 to before 1.83.7 allows authenticated users to execute arbitrary code within the LiteLLM Proxy process via a crafted prompt template, potentially exposing sensitive information and enabling command execution on the host.

LiteLLM ssti template-injection code-execution
2r 1t
high advisory

banks Library Vulnerable to Server-Side Template Injection Leading to Remote Code Execution

banks version 2.4.1 and earlier is vulnerable to Server-Side Template Injection (SSTI) due to the use of an unsandboxed Jinja2 environment, allowing attackers to achieve Remote Code Execution (RCE) by injecting malicious code through user-supplied prompt templates.

banks ssti rce jinja2
2r 2t 2c
critical advisory

Thymeleaf Server-Side Template Injection Vulnerability

Thymeleaf versions up to 3.1.3.RELEASE are vulnerable to server-side template injection (SSTI) due to improper neutralization of specific syntax patterns, allowing attackers to execute unauthorized expressions when unvalidated user input is passed directly to the template engine.

Thymeleaf +2 ssti cve-2026-40478 server-side template injection expression injection
2r 1t
critical threat

Grav CMS Multiple RCE Vulnerabilities

Multiple critical and high severity remote code execution vulnerabilities exist in Grav CMS due to unsafe unserialize functions, command injection in git clone, and an SSTI blocklist bypass, impacting versions prior to 2.0.0-beta.2.

Grav CMS +1 rce unserialize command-injection ssti
3r 2t
critical advisory

VMware Server-Side Template Injection Attempt (CVE-2022-22954)

An attacker attempts to exploit CVE-2022-22954, a server-side template injection vulnerability in VMware Workspace ONE Access and Identity Manager, by sending a crafted HTTP GET request containing malicious parameters to achieve remote code execution.

Workspace ONE Access +1 vmware ssti cve-2022-22954 template-injection
2r 2t
critical advisory

Thymeleaf Server-Side Template Injection Vulnerability

A server-side template injection vulnerability exists in Thymeleaf versions up to 3.1.4.RELEASE due to improper neutralization of specific constructs, allowing the execution of potentially dangerous expressions in sandboxed contexts if unsanitized variables are passed to the template engine.

thymeleaf +2 ssti template-injection cve-2026-41901
2r 1t
critical advisory

OpenMRS Stored Velocity SSTI to RCE via ConceptReferenceRange

OpenMRS is vulnerable to a Stored Velocity SSTI to RCE via ConceptReferenceRange, where the `ConceptReferenceRangeUtility.evaluateCriteria()` method evaluates database-stored criteria strings as Apache Velocity templates without a sandbox, allowing unrestricted Java reflection through template expressions, leading to persistent remote code execution and privilege escalation when a user with the `Manage Concepts` privilege stores a malicious Velocity template expression in a concept's reference range criteria field.

openmrs-api +1 ssti rce velocity openmrs
2r 2t