On this page
CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
Weakness Summary
The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
- Canonical source: MITRE CWE-1336 (opens in a new tab)
- Published Atomicorp CVE observations: 13
- Distinct affected products in those observations: 12
- Active Atomicorp rules associated with this weakness: 21
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2024-4040 | CrushFTP VFS - Sandbox Escape LFR | crushftp | Attack Blocked by Atomicorp | 392301 |
| CVE-2025-53833 | LaRecipe < 2.8.1 Remote Code Execution via SSTI | larecipe | Attack Blocked by Atomicorp | 340087 |
| CVE-2026-44181 | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution | enterprise gateway | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2025-23211 | Tandoor Recipes < 1.5.24 - Jinja2 SSTI RCE | recipes | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2024-23692 | Rejetto HTTP File Server - Template injection | http file server | Attack Blocked by Atomicorp | 344364 , 344366 , 390703 , 390722 |
| CVE-2026-55559 | Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance) | yamcs | Attack Blocked by Atomicorp | 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-28496 | FOSSBilling - Server-Side Template Injection | FOSSBilling | Attack Blocked by Atomicorp | 340130 , 340155 , 341155 |
| CVE-2026-28797 | RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Compone | ragflow | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72827 | Grav CMS before 2.0.13 Remote Code Execution via Twig | grav | Attack Blocked by Atomicorp | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-75574 | Grav before 4.2.2 Remote Code Execution via Email Twig | grav | Attack Blocked by Atomicorp | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-22244 | OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCE | openmetadata | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-77939 | Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint | flextype | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-78140 | Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine | UJCMS | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 330791 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340087 | Active | disruptive (deny) |
| 340130 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340155 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 341155 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 390703 | Active | disruptive (deny) |
| 390722 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |