template-injection
Safeguard articles tagged "template-injection" — guides, analysis, and best practices for software supply chain and application security.
7 articles
Adobe Commerce's CVSS 10.0 Went From Disclosure to Confirmed Exploitation in One Day
CVE-2026-75650, a server-side template injection in Adobe Commerce and Magento, was confirmed exploited within 24 hours of its NVD publication.
CVE-2024-22195: how Jinja2's xmlattr filter opened an XSS hole
A single filter in Jinja, xmlattr, could inject arbitrary HTML attributes and slip past autoescaping entirely — fixed in Jinja 3.1.3, tracked as CVE-2024-22195.
What Is SSTI (Server-Side Template Injection)?
SSTI happens when user input is compiled as template code instead of rendered as data, often leading straight to remote code execution. Here is how to prevent it.
Using EJS on npm Safely: CVE-2022-29078 and Beyond
The ejs npm package is a capable template engine that has also been the subject of a serious RCE advisory. Here is how to use it without opening that door.
ServiceNow CVE-2024-4879: Remote Code Execution via Jelly Template Injection
Critical RCE vulnerabilities in ServiceNow were chained together for unauthenticated access, with active exploitation observed within days of disclosure.
underscore.js template code injection (CVE-2021-23358)
CVE-2021-23358 lets attacker-controlled template settings inject arbitrary code via underscore.js's _.template function. Here's the impact, fix, and remediation steps.
EJS template engine RCE via client option (CVE-2022-29078)
CVE-2022-29078 lets attackers achieve remote code execution in EJS via unsanitized render options. Affected versions, severity, and fixes inside.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.