Most Rust template engines (Askama, Maud, Yarte) compile templates at build time from files in the source tree, so there is no runtime sink that parses attacker-controlled template text, and they are not injectable. The case that matters for SSTI is Tera, a Jinja2-inspired engine that parses templates at runtime and is therefore reachable when an application calls Tera::one_off or renders a template string built from user input.
Tera is another honest, limited case: like Go, it evaluates expressions and calls registered filters and functions but exposes no path to the Rust runtime, so impact is normally information disclosure rather than RCE.
Engines#
- Tera:
{{7*7}}confirmation, context and filter enumeration, and the limits that keep it to disclosure.
References#
- Tera documentation (Keats/tera)
- PortSwigger Web Security Academy: Server-side template injection