Ross ROSS = Recommend OSS · open-source software intelligence for agents

welk1n/JNDI-Injection-Exploit

JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc) observed · 2026-08-28

github.com/welk1n/JNDI-Injection-Exploit · Java · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2520
  • days_rel: n/a
  • days_push: 1260
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2823 stars · 728 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Java-based penetration testing tool that generates workable JNDI links and starts RMI, LDAP, and HTTP servers to exploit JNDI injection vulnerabilities. It is used to test whether applications like those using Fastjson or Jackson are vulnerable to JNDI injection leading to remote code execution.

Use cases

  • generate jndi links for testing jndi injection vulnerabilities
  • test fastjson deserialization rce poc
  • test jackson jndi injection vulnerability
  • start rmi and ldap servers for exploit delivery
  • verify java application remote code execution via jndi lookup

When to choose

  • you need to test your own Java applications for JNDI injection vulnerabilities
  • you want a ready-made tool to generate JNDI exploit links for POC validation
  • you need RMI, LDAP, and HTTP servers bundled in one exploit tool

When to avoid

  • you need a general-purpose vulnerability scanner rather than a single-technique exploit tool
  • your target is not a Java application using JNDI lookup
  • you require ongoing support or frequent updates, as the project is in maintenance mode

Facets

cli-tool · maturity maintenance

security penetration-testing http-server cli security penetration-testing developer-tools jvm cli cross-platform jndi-injection rmi-server ldap-server exploitation-tool java-deserialization vulnerability-testing

1 source

Member repositories

RepositoryRoleHealth v2
welk1n/JNDI-Injection-Exploitmain23

For agents

markdown · JSON · MCP: product_card(name="welk1n/JNDI-Injection-Exploit")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem