Aalexbit-codemod

java-server-side-template-injection-mining

Mine server-side template engine sinks (FreeMarker, Velocity, Thymeleaf, SpEL) built from dynamic templates (javasecurity:S5496); read-only metrics for security review

miningmetricsjavasecurityvulnerabilitysstitemplateinjectioncwe-94
Public
0 executions

Run locally

npx codemod java-server-side-template-injection-mining

java-server-side-template-injection-mining

Read-only mining codemod for SonarSource rule javasecurity:S5496Server-side templates should not be vulnerable to injection attacks.

It scans Java source and emits metrics only; it never modifies code (return null).
Findings are high-signal review candidates surfaced by AST pattern matching — they are
not proven vulnerabilities. A static mining pass cannot prove an end-to-end taint flow
from an untrusted source to the sink, so confirm data flow before remediating.

FieldValue
Rule keyjavasecurity:S5496
TypeVulnerability
SeverityBlocker
Primary CWECWE-94 (Code Injection)
Tagscwe, python3

What it detects

Server-side template engine sinks built from dynamic templates/expressions.

Sinks:

  • SpelExpressionParser.parseExpression(...)
  • Velocity.evaluate / VelocityEngine.evaluateString
  • TemplateEngine.process / createTemplate (Thymeleaf/Groovy)

Emission rule: Only emits when a template/expression argument is dynamic.

Metric: java-server-side-template-injection-mining

dimensionmeaning
ruleSonarSource rule key
cweprimary CWE identifier
severityalways blocker
sinkthe detected sink (method/constructor)
package_nameenclosing Java package
class_nameenclosing class/interface/enum/record
method_nameenclosing method/constructor (or <none>)
filefile path (relative to scan target)
line1-based line of the finding
arg_kindclassification of the relevant argument (literal, concatenation, variable, method_call, field, object_creation, expression, none)

Security standards

  • CWE-77 (Command Injection)
  • CWE-94 (Code Injection)
  • OWASP ASVS 4.0: 5.2.5, 5.2.8
  • OWASP Top 10 2021: A3
  • OWASP Top 10: A1
  • PCI DSS 3.2: 6.5.1
  • PCI DSS 4.0: 6.2.4
  • STIG ASD V5R3: V-222609

Run locally

bash

Part of the java-security-blocker-mining suite covering 19 blocker-severity
Java vulnerability rules. Each codemod is read-only and emits a single named metric.

Ready to contribute?

Build your own codemod and share it with the community.