SpEL

The Spring Expression Language (SpEL) evaluates expressions against an object graph at runtime. It appears throughout Spring: @Value annotations, Spring Security access rules, Spring Integration routing, Spring Data projections, and any code that calls a SpelExpressionParser directly. When request data reaches the string parsed into a SpEL expression, through a reflected parameter, a user-supplied rule, or a template value, the SpEL grammar runs inside the application.

SpEL is a full object language. The T(...) operator is a type reference that names any class on the classpath, and from there the expression calls static methods, constructs objects, and invokes instance methods. Under a StandardEvaluationContext, the default when code builds its own parser, that reaches java.lang.Runtime with no restriction. A SimpleEvaluationContext restricts the grammar, so the reachable surface depends on which context the application supplied.

  • Code execution: the type reference and reflection routes from a SpEL expression to the host runtime.
  • WAF bypass: rewriting the code-execution payload to defeat signature filters while keeping it valid SpEL.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more