← All Challenges
Challenge 43 of 66

Template Breaker

🟠 Hard Injection +100 XP

A web app uses Jinja2 templates and reflects user input into the template. Inject a Server-Side Template Injection payload.

Template Breaker // sandbox
Try {{7*7}} first. If it returns 49, the input is being evaluated as a template expression.

🏆 Challenge Complete!

+100 XP earned
Next Challenge →