Template Injection - Vulnerability

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 17, 2025
Last Seen
July 29, 2026

Template Injection is a web application vulnerability where user-supplied input is processed by a server-side templating engine, enabling attackers to inject template code and potentially achieve remote code execution, data exfiltration, or server compromise.

Overview

Template Injection is a web application vulnerability where user-supplied input is processed by a server-side templating engine, enabling attackers to inject template code and potentially achieve remote code execution, data exfiltration, or server compromise. It often arises when inputs are unsafely embedded in templates or when template features are overly permissive or misconfigured. Its significance lies in enabling stealthy, remote compromise across apps that rely on templating technologies such as Jinja2, Twig, Freemarker, and similar engines.

Related Threat Clusters

  • CVE-2023-5764 and CVE-2023-5115 Affect Ansible Users

    Two vulnerabilities in Ansible have been identified: CVE-2023-5764, a template injection issue, and CVE-2023-5115, which involves a malicious role archive that can disrupt Ansible operations. Both vulnerabilities were…

    2 articles · Updated February 18, 2026
  • OpenAI Launches GPT-5.4-Cyber Amidst Cybersecurity Arms Race

    OpenAI has introduced GPT-5.4-Cyber, a specialized AI model for defensive cybersecurity, available only to vetted professionals through its Trusted Access for Cyber (TAC) program. This model is designed to facilitate…

    1171 articles · Updated April 14, 2026
  • VulnCheck Launches Canary Intelligence for Real-Time Exploitation Data

    VulnCheck has launched Canary Intelligence, a tool that provides verified evidence of active exploitation from live, intentionally vulnerable systems. This product aims to assist security teams in confirming which…

    2 articles · Updated November 17, 2025
  • VulnCheck Launches Canary Intelligence for Real-Time Exploitation Evidence

    VulnCheck has launched Canary Intelligence, a tool that provides verified, first-party data on active exploitation of vulnerabilities from intentionally vulnerable systems. This product aims to enhance security teams'…

    2 articles · Updated November 17, 2025

Recent Intelligence Reports

  • Hugging Face Breach: AI Agent Security Lessons — Blog.Gitguardian · July 29, 2026
  • When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd) — Isc.Sans.Edu · July 23, 2026
  • Hugging Face Agentic Attacker Ai Breach 2026 — www.waxell.ai · July 21, 2026
  • CVE-2023-5764 Ansible: template injection — Api.Msrc.Microsoft · February 18, 2026
  • VulnCheck Launches Canary Intelligence to Provide Verified Evidence of Active Exploitation — Morningstar · November 17, 2025

CVSS v3.1 Breakdown