Comprehensive exploitation of Shiro deserialization vulnerabilities (for authorized testing only)
ShiroAttack2 is a security-testing tool for detecting and exploiting the Shiro-550 deserialization vulnerability in Apache Shiro applications. Authorized security testers use its command-line and JavaFX interfaces to test targets, validate keys, execute commands, and perform related post-exploitation actions. The catalogue entries include instructions, a plugin, and a skill for operating the tool.
Latest release v5.1.1 — ShiroAttack2 v5.1.1 · 27 May 2026
These files are SummerSec/ShiroAttack2's own configuration. They tell Codex, OpenCode and Claude Code how to work on this repository, so they are not mods to install elsewhere. Copy one as a starting point and replace the parts that are about this project.
AGENTS.md A 1,054 tok CLAUDE.md A 1,128 tok