expression-language-injection

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides numerous payloads designed to achieve remote code execution on target applications using Java Expression Languages (e.g., SpEL, OGNL, and Java EL). It also documents specific exploitation steps for CVEs such as CVE-2022-22947 (Spring Cloud Gateway) and CVE-2021-26084 (Confluence).
  • [COMMAND_EXECUTION]: Multiple examples of shell command execution strings are present (e.g., usage of Runtime.getRuntime().exec(), ProcessBuilder, and IOUtils for output capture). These are presented as payloads for the agent to use when testing remote systems.
  • [PRIVILEGE_ESCALATION]: The playbook details techniques for bypassing Java framework sandboxes and security restrictions, such as manipulating _memberAccess and clearing excludedClasses blacklists in Struts2 (OGNL) or using reflection to bypass SimpleEvaluationContext in SpEL.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:13 PM
Security Audit — agent-trust-hub — expression-language-injection