Skip to content

SSTI and Insecure Deserialization improvements based on the new version of my research#820

Merged
swisskyrepo merged 6 commits intoswisskyrepo:masterfrom
vladko312:master
Mar 2, 2026
Merged

SSTI and Insecure Deserialization improvements based on the new version of my research#820
swisskyrepo merged 6 commits intoswisskyrepo:masterfrom
vladko312:master

Conversation

@vladko312
Copy link
Copy Markdown
Contributor

SSTI:

  • Added Elixir/EEx payloads
  • Added OGNL payloads
  • Clarified SpEL payloads and details
  • Fixed PHP Error-Based payloads
  • Added Twig Error-Based payload for CVE-2022-23614
    Insecure Deserialization:
  • Improved Python payloads

- Added Elixir/EEx payloads
- Added OGNL payloads
- Clarified SpEL payloads and details
- Fixed PHP Error-Based payloads
- Added Twig Error-Based payload for CVE-2022-23614
Insecure Deserialization:
- Improved Python payloads
@vladko312 vladko312 changed the title SSTI and Insecured Deserialization improvements based on the new version of my research SSTI and Insecure Deserialization improvements based on the new version of my research Feb 22, 2026
Removed note about platform-specific payloads and added information on creating a universal payload using eval.
Updated the title and provided a brief overview of Server-Side Template Injection in Elixir.
@swisskyrepo swisskyrepo merged commit 2e32d27 into swisskyrepo:master Mar 2, 2026
1 check failed
@vladko312
Copy link
Copy Markdown
Contributor Author

@swisskyrepo Why was Elixir SSTI page renamed to Elixir deserialization? The only changes for insecure deserialization were regarding python payloads

@swisskyrepo
Copy link
Copy Markdown
Owner

@swisskyrepo Why was Elixir SSTI page renamed to Elixir deserialization? The only changes for insecure deserialization were regarding python payloads

Because I'm an idiot😅
It is fixed in d8e749c

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants