nyx/tests/fixtures/ssti/python/safe_jinja_constant.py
2026-05-07 01:29:31 -04:00

9 lines
306 B
Python

# Safe: jinja2.Template receives a constant template source. Variables
# passed at render time are not template source and do not activate SSTI.
from jinja2 import Template
from flask import request
def handler():
t = Template("Hello, {{ name }}")
return t.render(name=request.args.get("name"))