Go's standard templating is text/template and its auto-escaping sibling html/template. Both are deliberately restricted: a template can reference fields and call methods on the data passed to it, but it cannot import packages, construct arbitrary types, or reach the runtime. This makes Go an important honest case: injecting template syntax rarely yields command execution the way Jinja2 or FreeMarker do.
Engines#
- text/template and html/template: detection, field and method enumeration, information disclosure, and the method-call conditions under which impact escalates.
References#
- Go documentation: text/template, html/template
- PortSwigger Web Security Academy: Server-side template injection