Template engines play a pivotal role in modern web application development by enabling the dynamic rendering of content, products, and user interfaces. Today, they are essential for any website that handles dynamic data, from e-commerce to social media. However, their widespread adoption also makes them attractive targets for attackers seeking to exploit vulnerabilities and gain unauthorized access to web servers. This paper presents a comprehensive assessment of the risks associated with template engines, with a particular focus on the consequences of Server-Side Template Injection (SSTI) and the ease with which such vulnerabilities can escalate to Remote Code Execution (RCE), a critical security concern in web application development.

An Assessment of the Overlooked Dangers of Template Engines

Pisu, Lorenzo
;
Maiorca, Davide;Giacinto, Giorgio
2026-01-01

Abstract

Template engines play a pivotal role in modern web application development by enabling the dynamic rendering of content, products, and user interfaces. Today, they are essential for any website that handles dynamic data, from e-commerce to social media. However, their widespread adoption also makes them attractive targets for attackers seeking to exploit vulnerabilities and gain unauthorized access to web servers. This paper presents a comprehensive assessment of the risks associated with template engines, with a particular focus on the consequences of Server-Side Template Injection (SSTI) and the ease with which such vulnerabilities can escalate to Remote Code Execution (RCE), a critical security concern in web application development.
2026
Template Engine; Server-Side Template Injection; SSTI
File in questo prodotto:
File Dimensione Formato  
3799796 (2).pdf

Solo gestori archivio

Tipologia: versione pre-print
Dimensione 538.83 kB
Formato Adobe PDF
538.83 kB Adobe PDF   Visualizza/Apri   Richiedi una copia
3799796.pdf

accesso aperto

Tipologia: versione post-print (AAM)
Dimensione 471.88 kB
Formato Adobe PDF
471.88 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11584/477446
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact