welk1n/JNDI-Injection-Exploit
JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc) observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2520
- days_rel: n/a
- days_push: 1260
- n_releases_24m: 0
Adoption not part of the score
2823 stars · 728 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A Java-based penetration testing tool that generates workable JNDI links and starts RMI, LDAP, and HTTP servers to exploit JNDI injection vulnerabilities. It is used to test whether applications like those using Fastjson or Jackson are vulnerable to JNDI injection leading to remote code execution.
Use cases
- generate jndi links for testing jndi injection vulnerabilities
- test fastjson deserialization rce poc
- test jackson jndi injection vulnerability
- start rmi and ldap servers for exploit delivery
- verify java application remote code execution via jndi lookup
When to choose
- you need to test your own Java applications for JNDI injection vulnerabilities
- you want a ready-made tool to generate JNDI exploit links for POC validation
- you need RMI, LDAP, and HTTP servers bundled in one exploit tool
When to avoid
- you need a general-purpose vulnerability scanner rather than a single-technique exploit tool
- your target is not a Java application using JNDI lookup
- you require ongoing support or frequent updates, as the project is in maintenance mode
Facets
cli-tool · maturity maintenance
security penetration-testing http-server cli security penetration-testing developer-tools jvm cli cross-platform jndi-injection rmi-server ldap-server exploitation-tool java-deserialization vulnerability-testing
1 source
- readme: https://github.com/welk1n/JNDI-Injection-Exploit · fetched 2026-08-28 · 0edb8dbfa15a
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| welk1n/JNDI-Injection-Exploit | main | 23 |
For agents
markdown · JSON · MCP: product_card(name="welk1n/JNDI-Injection-Exploit")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem