Skip to main content

ssti

Hunt server-side template injection across Jinja2/Twig/Freemarker/Velocity/Handlebars and validate progression from expression injection to code execution.

Jump to install

Source facts

Repository
BitterSecurity/Decepticon
Last source activity
June 2, 2026 at 17:42
Detected SKILL.md language
English
Stars
5,611
Forks
1,061

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.

Showing SKILL.md

SKILL.md
Source instructions · Read-only preview
name
ssti
description
Hunt server-side template injection across Jinja2/Twig/Freemarker/Velocity/Handlebars and validate progression from expression injection to code execution.
metadata
{"subdomain":"web-exploitation","when_to_use":"ssti server side template injection jinja2 twig freemarker velocity handlebars expression code execution"}
# SSTI Playbook ## High-signal checks - Look for template rendering with user input in `render_template_string`, `Template(...)`, `twig->createTemplate`, `Freemarker Template.process`. - Confirm user-controlled payload reaches a template context key or template source string. ## Fast probes - Jinja2: `{{7*7}}`, `{{config}}`, `{{request}}` - Twig: `{{7*7}}`, `{{_self}}` - Freemarker: `${7*7}` - Velocity: `#set($x=7*7)$x` ## Escalation path 1. Detect expression evaluation. 2. Enumerate available objects and filters. 3. Attempt file read / env leak. 4. Attempt command execution via framework-specific gadget chain. ## Validation Use `validate_finding` with a positive execution signal and a benign negative control.
View on GitHub