BaseIncomplete
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Category: other
Description
The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
Common consequences· 1
- Integrity — Execute Unauthorized Code or Commands
Potential mitigations· 2
- [Architecture and Design]Choose a template engine that offers a sandbox or restricted mode, or at least limits the power of any available expressions, function calls, or commands.
- [Implementation]Use the template engine's sandbox or restricted mode, if available.
References
Compliance frameworks addressing this (incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| ComplianceControl | owasp_llm_top10-llm07 | 100% | live |
(incoming)57
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-10380cve-2025-10380 | 0% | live |
| Vulnerability | CVE-2025-1040cve-2025-1040 | 0% | live |
| Vulnerability | CVE-2025-14700cve-2025-14700 | 0% | live |
| Vulnerability | CVE-2025-23211cve-2025-23211 | 0% | live |
| Vulnerability | CVE-2025-27516cve-2025-27516 | 0% | live |
| Vulnerability | CVE-2025-32461cve-2025-32461 | 0% | live |
| Vulnerability | CVE-2025-3841cve-2025-3841 | 0% | live |
| Vulnerability | CVE-2025-46661cve-2025-46661 | 0% | live |
| Vulnerability | CVE-2025-47916cve-2025-47916 | 0% | live |
| Vulnerability | CVE-2025-49619cve-2025-49619 | 0% | live |
| Vulnerability | CVE-2025-49828cve-2025-49828 | 0% | live |
| Vulnerability | CVE-2025-52122cve-2025-52122 | 0% | live |
| Vulnerability | CVE-2025-5325cve-2025-5325 | 0% | live |
| Vulnerability | CVE-2025-53833cve-2025-53833 | 0% | live |
| Vulnerability | CVE-2025-59340cve-2025-59340 | 0% | live |
| Vulnerability | CVE-2025-60355cve-2025-60355 | 0% | live |
| Vulnerability | CVE-2025-64087cve-2025-64087 | 0% | live |
| Vulnerability | CVE-2025-65602cve-2025-65602 | 0% | live |
| Vulnerability | CVE-2025-66294cve-2025-66294 | 0% | live |
| Vulnerability | CVE-2025-66297cve-2025-66297 | 0% | live |
| Vulnerability | CVE-2025-66299cve-2025-66299 | 0% | live |
| Vulnerability | CVE-2025-66434cve-2025-66434 | 0% | live |
| Vulnerability | CVE-2025-66437cve-2025-66437 | 0% | live |
| Vulnerability | CVE-2025-66438cve-2025-66438 | 0% | live |
| Vulnerability | CVE-2025-67843cve-2025-67843 | 0% | live |
| Vulnerability | CVE-2025-68454cve-2025-68454 | 0% | live |
| Vulnerability | CVE-2025-68929cve-2025-68929 | 0% | live |
| Vulnerability | CVE-2025-69516cve-2025-69516 | 0% | live |
| Vulnerability | CVE-2026-1868cve-2026-1868 | 0% | live |
| Vulnerability | CVE-2026-21448cve-2026-21448 | 0% | live |
Showing top 30 of 57 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.