home/categories/framework-internals/yaklang-hack-skills-skills-expression-language-injection-skill-md
framework-internalsdevelopment
expression-language-injection
Expression Language injection playbook. Use when Java EL, SpEL, OGNL, or MVEL expressions may evaluate attacker-controlled input in Spring, Struts2, Confluence, or similar frameworks.
maintainer
yaklang
Updated 4/8/2026
Stars
83
Forks
10
quick start
Installation and usage
Expression Language injection playbook. Use when Java EL, SpEL, OGNL, or MVEL expressions may evaluate attacker-controlled input in Spring, Struts2, Confluence, or similar frameworks.
Installation
$ install --globalskills.sh
Usage
Once installed, you can use this skill by running the following command in your terminal:
skills use expression-language-injection