bolt-cms-pentesting
How to exploit Bolt CMS for Remote Code Execution (RCE) via Twig template injection. Use this skill when pentesting Bolt CMS installations, when you need to check for SSTI vulnerabilities in Bolt CMS, or when you have admin access to a Bolt CMS instance and want to escalate to RCE. This skill covers the complete exploitation chain from admin login to code execution.
Source facts
- Repository
- abelrguezr/hacktricks-skills
- Last source activity
- March 23, 2026 at 14:29
- Detected SKILL.md language
- English
- Stars
- 21
- Forks
- 8
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.