CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

Parent: CWE-94 - Improper Control of Generation of Code ('Code Injection')

The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

193 vulnerabilities with CWE-1336
CVE-2026-54666 HIGH
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
CVSS 8.3
CVE-2026-54664 HIGH
swagger-typescript-api vulnerable to code injection via unescaped enum string values
CVSS 8.3
CVE-2026-54662 HIGH
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
CVSS 8.3
CVE-2026-54661 HIGH
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
CVSS 8.3
CVE-2026-9177 CRITICAL
Server-Side Template Injection in SecureTransport's Apache Velocity mail templates
CVE-2026-54654 HIGH
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
CVSS 7.8
CVE-2026-54653 HIGH
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
CVSS 8.8
CVE-2026-54621 HIGH
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
CVSS 7.8
CVE-2026-47752 CRITICAL
Tugtainer has Server-Side Template Injection in notification templates that leads to Remote Code Execution
CVSS 9.9
CVE-2026-47690 HIGH
MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflow
CVSS 7.5
CVE-2026-63728 MEDIUM
Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature
CVSS 6.3
CVE-2026-44181 CRITICAL
Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution
CVE-2026-55242 HIGH
ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix
CVSS 8.8
CVE-2026-55794 HIGH
Craft CMS: Potential authenticated Remote Code Execution via referrer redirect
CVE-2026-52796 LOW
Gogs < 0.14.3 - Repository Index Pattern Panic Denial of Service
CVSS 3.5
CVE-2026-28496 CRITICAL
FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE
CVE-2026-54390 CRITICAL
JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer
CVSS 9.8
CVE-2026-11407 HIGH
Pimcore CMS 12.3.8 Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
CVSS 7.2
CVE-2026-41065 HIGH
Tautulli Vulnerable to Unauthenticated/Authenticated Remote Code Execution via Newsletter Custom Template Directory
CVE-2026-34906 CRITICAL
Server-Side Template Injection (SSTI) in Wirtualna Uczelnia
CVE-2026-42252 CRITICAL
Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern
CVSS 9.1
CVE-2026-45697 CRITICAL
Formie: Pre-authenticated server-side template injection in Hidden fields
CVSS 9.8
CVE-2026-49382 MEDIUM
Jetbrains IntelliJ Idea < 2026.1 - Improper Neutralization of Special Elements Used in a Template Engine
CVSS 4.5
CVE-2026-45312 CRITICAL
RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution
CVSS 9.9
CVE-2026-9558 CRITICAL
Mautic - Authenticated Server-Side Template Injection via Theme Engine
CVSS 9.9
Details
Vulnerabilities 193