expression-language-injection
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides numerous payloads designed to achieve remote code execution on target applications using Java Expression Languages (e.g., SpEL, OGNL, and Java EL). It also documents specific exploitation steps for CVEs such as CVE-2022-22947 (Spring Cloud Gateway) and CVE-2021-26084 (Confluence).
- [COMMAND_EXECUTION]: Multiple examples of shell command execution strings are present (e.g., usage of
Runtime.getRuntime().exec(),ProcessBuilder, andIOUtilsfor output capture). These are presented as payloads for the agent to use when testing remote systems. - [PRIVILEGE_ESCALATION]: The playbook details techniques for bypassing Java framework sandboxes and security restrictions, such as manipulating
_memberAccessand clearingexcludedClassesblacklists in Struts2 (OGNL) or using reflection to bypassSimpleEvaluationContextin SpEL.
Audit Metadata