Back to Skills

expression-language-injection

Expression Language injection playbook. Use when Java EL, SpEL, OGNL, or MVEL expressions may evaluate attacker-controlled input in Spring, Struts2, Confluence, or similar frameworks.

1,292stars177forksUpdated 7/6/2026

Security Assessment

Critical Risk(15/100)

Detected risks:

Agent-reviewed override(Offensive attack playbook (RCE via SpEL/OGNL/Java EL — Spring Cloud Gateway CVE-2022-22947, Struts2/Confluence). Import attached no SKILL.md so the assessor defaulted to safe; scored manually from the real GitHub content. Genuine offensive tooling, per gotcha #7.)
Security Score15/100

About expression-language-injection

An Expression Language (EL) injection attack playbook for authorized security testing, covering Spring Expression Language (SpEL), OGNL, and Java EL (JSP/JSF). It draws a clear line between EL injection, which targets expression evaluators embedded in Java frameworks, and server-side template injection, which targets template engines, noting that the two share detection probes but diverge in exploitation. Detection starts with polyglot arithmetic probes in the different EL syntaxes and a disambiguation table that maps responses to the underlying engine. The SpEL section describes where the language appears (value annotations, Spring Security expressions, Spring Cloud Gateway, Spring Data queries) and how command execution and output capture are achieved, including a reflection-based sandbox bypass when a restricted evaluation context is used, and the Spring Cloud Gateway actuator route-injection technique (CVE-2022-22947) with cleanup steps for stealth. The OGNL section focuses on Apache Struts2 and Confluence, covering the classic _memberAccess manipulation and blacklist-clearing bypasses and a table of key Struts2 CVEs (S2-045, S2-046, S2-016, S2-048, S2-057) plus Confluence's CVE-2021-26084. A final section addresses Java EL in JSP and JSF, including reflection-based payloads. The material is intended for penetration testers and security researchers operating under authorization.

FAQ

How is EL injection different from SSTI?

EL injection targets expression evaluators embedded in Java frameworks (SpEL, OGNL, Java EL), whereas SSTI targets template-rendering engines like Jinja2 or FreeMarker; they can share probes but differ in exploitation.

Which engines and frameworks does it cover?

SpEL (Spring, Spring Security, Spring Cloud Gateway, Spring Data), OGNL (Apache Struts2, Confluence), and Java EL (JSP/JSF).

How do you identify which engine is in use?

It provides polyglot probes in the different EL syntaxes and a disambiguation table mapping which probe evaluates, to distinguish SpEL, OGNL, or Java EL.

What notable CVEs are referenced?

Spring Cloud Gateway CVE-2022-22947, Confluence CVE-2021-26084, and Struts2 CVEs including S2-045, S2-046, S2-016, S2-048, and S2-057.

Does it handle sandboxed expression contexts?

Yes; it covers bypasses for restricted contexts, such as reflection-based approaches when SpEL uses a limited evaluation context, and Struts2 _memberAccess/blacklist clearing.

Install expression-language-injection

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill