RLAgent-GSSTI: Automated Grey-Box SSTI Vulnerability Detection Based on Reinforcement Learning Agent
Summary
This paper presents RLAgent-GSSTI, a framework that uses reinforcement learning (RL, a machine learning technique where a system learns by receiving rewards for good actions) to automatically detect SSTI vulnerabilities (server-side template injection, where attackers manipulate template engines to execute unintended code on web servers). The framework combines code analysis tools with AI agents to both predict SSTI risks and generate attack payloads to identify vulnerabilities, achieving much lower false negative rates (missed vulnerabilities) compared to traditional security scanning tools.
Classification
Original source: http://ieeexplore.ieee.org/document/11660868
First tracked: September 7, 2026 at 08:03 PM
Classified by LLM (prompt v3) · confidence: 85%