Ruby SSTI centers on ERB, the standard embedded-Ruby engine used by Rails and many standalone apps (with Erubi and Erubis as compatible variants). ERB evaluates Ruby inside its tags with no sandbox, so a template injection is direct code execution: there is no object graph to walk and no built-in to escape.
Detection uses ERB's own tag syntax rather than {{7*7}}, since ERB executes <%= ... %>. The escalation is immediate through Ruby's backticks, system, IO.popen, or %x{}.
Engines#
- ERB:
<%=command%>and thesystem/IO.popenvariants, plus the Railsrender inline:sink.
References#
- Ruby ERB and Erubi documentation
- PortSwigger Web Security Academy: Server-side template injection