lijiejie/swagger-exp
A Swagger API Exploit observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 1989
- days_rel: n/a
- days_push: 817
- n_releases_24m: 0
Adoption not part of the score
1381 stars · 135 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A Python-based Swagger REST API information disclosure exploitation tool. It enumerates API endpoints, auto-fills parameters, tests for unauthorized access and auth bypass, detects SSRF-prone parameters, and serves a local Swagger UI with CORS disabled for manual testing.
Use cases
- scan a swagger api for unauthorized access
- test openapi endpoints for auth bypass
- find ssrf vulnerabilities in api parameters
- open swagger ui locally with cors disabled
- enumerate all rest api endpoints from swagger docs
- pentest a site's api-docs
When to choose
- you need to quickly assess exposure of a Swagger/OpenAPI-documented API during authorized pentesting
- you want automated endpoint enumeration plus a local Swagger UI for manual testing
When to avoid
- the target API has no Swagger/OpenAPI documentation
- you need a full-featured API security scanner or CI-integrated vulnerability scanning
- you require a maintained, licensed tool for production security workflows
Facets
cli-tool · maturity maintenance
penetration-testing security http-client web-scraping security penetration-testing apis developer-tools python cli cross-platform swagger openapi api-security information-disclosure unauthorized-access ssrf swagger-ui
1 source
- readme: https://github.com/lijiejie/swagger-exp · fetched 2026-08-28 · aaae059041ff
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| lijiejie/swagger-exp | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="lijiejie/swagger-exp")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem