> For the complete documentation index, see [llms.txt](https://heapbytes.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://heapbytes.gitbook.io/notes/web-security/ssti.md).

# SSTI

Server Side Template Injection.

> Resources, payloads & CTF Writeups

## Resources

{% embed url="<https://book.hacktricks.wiki/en/pentesting-web/ssti-server-side-template-injection/jinja2-ssti.html>" %}

{% embed url="<https://www.onsecurity.io/blog/server-side-template-injection-with-jinja2/>" %}

{% embed url="<https://www.onsecurity.io/blog/go-ssti-method-research/>" %}
