SummerSec/ShiroAttack2

Comprehensive exploitation of Shiro deserialization vulnerabilities (for authorized testing only)

About the project

ShiroAttack2 is a security-testing tool for detecting and exploiting the Shiro-550 deserialization vulnerability in Apache Shiro applications. Authorized security testers use its command-line and JavaFX interfaces to test targets, validate keys, execute commands, and perform related post-exploitation actions. The catalogue entries include instructions, a plugin, and a skill for operating the tool.

Latest release v5.1.1 — ShiroAttack2 v5.1.1 · 27 May 2026

These files are SummerSec/ShiroAttack2's own configuration. They tell Codex, OpenCode and Claude Code how to work on this repository, so they are not mods to install elsewhere. Copy one as a starting point and replace the parts that are about this project.

2,625Stars on the repository
2Files it configures its agents with
2,182Tokens loaded in every session
3Agents configured

Instructions