CWE-1336— Improper Neutralization of Special Elements Used in a Template Engine (SSTI)
The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.— MITRE CWE catalog
259 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1336page 5 of 6
- CVE-2026-54653HIGHCVSS 8.8EG 8.82026-07-28
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.17.0 until 0.60.2, datamodel-code-generator preserves…
- CVE-2026-54654HIGHCVSS 7.8EG 7.82026-07-28
datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-template-data comment field is rendered into Python comments in src/datamodel_code_generator/model/template/TypeAliasAnnot…
- CVE-2026-54661HIGHCVSS 8.3EG 8.32026-07-29
swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient…
- CVE-2026-54662HIGHCVSS 8.3EG 8.32026-07-29
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http…
- CVE-2026-54664HIGHCVSS 8.3EG 8.32026-07-29
swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuratio…
- CVE-2026-54666HIGHCVSS 8.3EG 8.32026-07-29
swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and…
- CVE-2026-54718HIGHCVSS 7.2EG 7.22026-08-27
Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side temp…
- CVE-2026-55242HIGHCVSS 8.8EG 8.82026-07-15
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting …
- CVE-2026-55559CRITICALCVSS 9.8EG 9.82026-08-28
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templatin…
- CVE-2026-5559MEDIUMCVSS 6.3EG 6.32026-04-05
A vulnerability has been found in AntaresMugisho PyBlade 0.1.8-alpha/0.1.9-alpha. The affected element is the function _is_safe_ast of the file sandbox.py of the component AST Validation. Such manipulation leads to improper neutralization …
- CVE-2026-55794HIGHCVSS 8.7EG 8.72026-07-02
Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header, potentially leading to authen…
- CVE-2026-57170HIGHCVSS 7.8EG 7.82026-08-25
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse…
- CVE-2026-5987MEDIUMCVSS 4.7EG 4.72026-04-09
A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFreemarkerView.doRender of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/common/base/AbstractFreemar…
- CVE-2026-59989CRITICALCVSS 9.2EG 9.22026-08-21
Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the join filter by inserting the raw separator and array token values into generated PHP with…
- CVE-2026-62681CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch, r…
- CVE-2026-62682CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in servers[0].url is emitted into request URL template literals generated when output.baseUrl.…
- CVE-2026-63728MEDIUMCVSS 6.3EG 6.32026-07-20
Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig …
- CVE-2026-65974CRITICALCVSS 9.9EG 9.92026-08-17
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forc…
- CVE-2026-66613CRITICALCVSS 9.8EG 9.82026-08-19
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
- CVE-2026-69118HIGHCVSS 8.8EG 8.82026-08-10
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade directi…
- CVE-2026-6984MEDIUMCVSS 4.7EG 4.72026-04-25
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard API. The manipulation results in improper neutralizat…
- CVE-2026-71239HIGHCVSS 8.1EG 8.12026-08-05
DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subj…
- CVE-2026-71286MEDIUMCVSS 6.1EG 6.12026-08-05
The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property directly into Ember/Glimmer's compileTemplate (from @ember/template-compilation) with no sanitization, allow-listing, …
- CVE-2026-71291HIGHCVSS 8.8EG 8.82026-08-05
Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTwigValue calls shouldBeRenderedAsTwig, which gates rendering…
- CVE-2026-71502MEDIUMCVSS 5.1EG 5.12026-08-06
CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conver…
- CVE-2026-71868CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum default is emitted into a module-level template literal emitted by zod sc…
- CVE-2026-71869CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an array item default is emitted into a module-level template literal emitted by …
- CVE-2026-71871CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header parameter default is emitted into a module-level template literal emitte…
- CVE-2026-71880HIGHCVSS 7.6EG 7.62026-08-18
Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via template injection
- CVE-2026-72716CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a query parameter default is emitted into a module-level template literal emitted…
- CVE-2026-72717CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-level template literal emitted by zod s…
- CVE-2026-72827HIGHCVSS 8.8EG 8.82026-08-14
Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject Twig payloads using the …
- CVE-2026-72911CRITICALCVSS 9.9EG 9.92026-08-10
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py …
- CVE-2026-73299CRITICALCVSS 10.0EG 10.02026-08-12
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled…
- CVE-2026-73330MEDIUMCVSS 6.6EG 6.62026-08-12
CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are eval…
- CVE-2026-73505HIGHCVSS 7.8EG 7.82026-07-24
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function…
- CVE-2026-75036MEDIUMCVSS 5.3EG 5.32026-09-03
A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a reposi…
- CVE-2026-75574HIGHCVSS 8.8EG 8.82026-08-25
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can plac…
- CVE-2026-75650CRITICALCVSS 10.0EG 10.0⚠ KEV2026-09-07
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerabi…
- CVE-2026-75829HIGHCVSS 8.1EG 8.12026-08-18
grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and conten…
- CVE-2026-75979MEDIUMCVSS 6.3EG 6.32026-08-19
A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sqlT…
- CVE-2026-77129HIGHCVSS 7.7EG 7.72026-08-25
The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this fi…
- CVE-2026-77136CRITICALCVSS 9.5EG 9.52026-08-25
The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can s…
- CVE-2026-77939MEDIUMCVSS 6.5EG 6.52026-08-28
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony Expression…
- CVE-2026-78140MEDIUMCVSS 4.7EG 4.72026-08-23
A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component web-file-template Endpoint. Executi…
- CVE-2026-81910MEDIUMCVSS 6.5EG 6.52026-09-11
Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle …
- CVE-2026-82447HIGHCVSS 8.8EG 8.82026-08-29
Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja temp…
- CVE-2026-82958HIGHCVSS 7.6EG 7.62026-09-02
In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_id }}) resolved from inbound message header…
- CVE-2026-85654HIGHCVSS 7.8EG 7.82026-09-04
Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the gene…
- CVE-2026-87021HIGHCVSS 7.2EG 7.22026-09-09
Tanium addressed an unauthorized code execution vulnerability in Comply.
Map vulnerabilities like CWE-1336 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1336 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →