Server-side template injection TL;DR: User input rendered as a template expression by Jinja/Twig/Velocity/etc. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References https://portswigger.net/web-security/server-side-template-injection