> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# SSTI (Server-Side Template Injection)

> Cross-platform resources for SSTI (Server-Side Template Injection): curated HTB machines, PortSwigger labs and TryHackMe rooms with validated writeups and related skills.

# SSTI (Server-Side Template Injection)

This page aggregates **cross-platform resources to practice SSTI (Server-Side Template Injection)**: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills.

## Curated resources

| Source      | Link                                                                                                                                       |
| ----------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
| PortSwigger | [https://portswigger.net/web-security/server-side-template-injection](https://portswigger.net/web-security/server-side-template-injection) |

## HTB machines practicing SSTI (Server-Side Template Injection) (12)

| Machine                                                 | OS      | Difficulty                                           |
| ------------------------------------------------------- | ------- | ---------------------------------------------------- |
| [Anubis](/en/htb/machines/windows/insano/anubis)        | Windows | <span className="dbadge dbadge-insane">INSANE</span> |
| [Bolt](/en/htb/machines/linux/medio/bolt)               | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [Catch](/en/htb/machines/linux/medio/catch)             | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [Doctor](/en/htb/machines/linux/facil/doctor)           | Linux   | <span className="dbadge dbadge-easy">EASY</span>     |
| [Epsilon](/en/htb/machines/linux/medio/epsilon)         | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [Flustered](/en/htb/machines/linux/medio/flustered)     | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [GoodGames](/en/htb/machines/linux/facil/goodgames)     | Linux   | <span className="dbadge dbadge-easy">EASY</span>     |
| [Hancliffe](/en/htb/machines/windows/dificil/hancliffe) | Windows | <span className="dbadge dbadge-hard">HARD</span>     |
| [Late](/en/htb/machines/linux/facil/late)               | Linux   | <span className="dbadge dbadge-easy">EASY</span>     |
| [Noter](/en/htb/machines/linux/medio/noter)             | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [NunChucks](/en/htb/machines/linux/facil/nunchucks)     | Linux   | <span className="dbadge dbadge-easy">EASY</span>     |
| [Oz](/en/htb/machines/linux/dificil/oz)                 | Linux   | <span className="dbadge dbadge-hard">HARD</span>     |

## PortSwigger labs practicing SSTI (Server-Side Template Injection) (7)

| Lab                                                                                                                                                                                                                                         | Difficulty                                                 | Topic                                 | Official                                                                                                                                                                        |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- | ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [Server-side template injection in a sandboxed environment](/en/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-in-a-sandboxed-environment)                                                       | <span className="dbadge dbadge-easy">APPRENTICE</span>     | Server-Side Template Injection (SSTI) | [Open](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-in-a-sandboxed-environment)                            |
| [Server-side template injection with a custom exploit](/en/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-with-a-custom-exploit)                                                                 | <span className="dbadge dbadge-easy">APPRENTICE</span>     | Server-Side Template Injection (SSTI) | [Open](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-with-a-custom-exploit)                                 |
| [Basic server-side template injection](/en/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-basic)                                                                                                 | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Server-Side Template Injection (SSTI) | [Open](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-basic)                                                 |
| [Basic server-side template injection (code context)](/en/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-basic-code-context)                                                                     | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Server-Side Template Injection (SSTI) | [Open](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-basic-code-context)                                    |
| [Server-side template injection in an unknown language with a documented exploit](/en/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-in-an-unknown-language-with-a-documented-exploit)           | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Server-Side Template Injection (SSTI) | [Open](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-in-an-unknown-language-with-a-documented-exploit)      |
| [Server-side template injection using documentation](/en/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-using-documentation)                                                                     | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Server-Side Template Injection (SSTI) | [Open](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-using-documentation)                                   |
| [Server-side template injection with information disclosure via user-supplied objects](/en/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-with-information-disclosure-via-user-supplied-objects) | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Server-Side Template Injection (SSTI) | [Open](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-with-information-disclosure-via-user-supplied-objects) |

## TryHackMe rooms practicing SSTI (Server-Side Template Injection) (5)

| Room                                                                                  | Difficulty                                         | Type        | Access  | Official                                                       |
| ------------------------------------------------------------------------------------- | -------------------------------------------------- | ----------- | ------- | -------------------------------------------------------------- |
| [OWASP Top 10 2025: Insecure Data Handling](/en/tryhackme/rooms/owasptopten2025three) | <span className="dbadge dbadge-easy">EASY</span>   | Walkthrough | 🟢 Free | [Open](https://tryhackme.com/room/owasptopten2025three)        |
| [Hip Flask](/en/tryhackme/rooms/hipflask)                                             | <span className="dbadge dbadge-easy">MEDIUM</span> | Walkthrough | 🟢 Free | [Open](https://tryhackme.com/room/hipflask)                    |
| [NoNameCTF](/en/tryhackme/rooms/nonamectf)                                            | <span className="dbadge dbadge-easy">MEDIUM</span> | Challenge   | 🔵 VIP  | [Open](https://tryhackme.com/room/nonamectf)                   |
| [Server-side Template Injection](/en/tryhackme/rooms/serversidetemplateinjection)     | <span className="dbadge dbadge-easy">MEDIUM</span> | Walkthrough | 🔵 VIP  | [Open](https://tryhackme.com/room/serversidetemplateinjection) |
| [SSTI](/en/tryhackme/rooms/learnssti)                                                 | <span className="dbadge dbadge-easy">MEDIUM</span> | Walkthrough | 🟢 Free | [Open](https://tryhackme.com/room/learnssti)                   |

## Related skills

* [/en/skills/rce](/en/skills/rce)

***

← [Back to the full glossary](/en/glossary)

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"DefinedTerm","name":"SSTI (Server-Side Template Injection)","termCode":"ssti","inLanguage":"en","url":"https://rootea.es/en/skills/ssti","inDefinedTermSet":{"@type":"DefinedTermSet","name":"Tactical pentesting glossary","url":"https://rootea.es/en/glossary"}}`}
</script>

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"ItemList","name":"HTB machines practicing SSTI (Server-Side Template Injection)","numberOfItems":12,"itemListElement":[{"@type":"ListItem","position":1,"url":"https://rootea.es/en/htb/machines/windows/insano/anubis","name":"Anubis"},{"@type":"ListItem","position":2,"url":"https://rootea.es/en/htb/machines/linux/medio/bolt","name":"Bolt"},{"@type":"ListItem","position":3,"url":"https://rootea.es/en/htb/machines/linux/medio/catch","name":"Catch"},{"@type":"ListItem","position":4,"url":"https://rootea.es/en/htb/machines/linux/facil/doctor","name":"Doctor"},{"@type":"ListItem","position":5,"url":"https://rootea.es/en/htb/machines/linux/medio/epsilon","name":"Epsilon"},{"@type":"ListItem","position":6,"url":"https://rootea.es/en/htb/machines/linux/medio/flustered","name":"Flustered"},{"@type":"ListItem","position":7,"url":"https://rootea.es/en/htb/machines/linux/facil/goodgames","name":"GoodGames"},{"@type":"ListItem","position":8,"url":"https://rootea.es/en/htb/machines/windows/dificil/hancliffe","name":"Hancliffe"},{"@type":"ListItem","position":9,"url":"https://rootea.es/en/htb/machines/linux/facil/late","name":"Late"},{"@type":"ListItem","position":10,"url":"https://rootea.es/en/htb/machines/linux/medio/noter","name":"Noter"},{"@type":"ListItem","position":11,"url":"https://rootea.es/en/htb/machines/linux/facil/nunchucks","name":"NunChucks"},{"@type":"ListItem","position":12,"url":"https://rootea.es/en/htb/machines/linux/dificil/oz","name":"Oz"}]}`}
</script>

*Last updated: 2026-06-07*
