
Asynchronous scanner and exploit tool for CVE-2025-5777 (CitrixBleed 2). Detects memory leaks in NetScaler ADC/Gateway, parses sensitive data like session cookies, and generates reports for authorized security testing.

An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the vulnerability but also helps in demonstrating its impact by parsing human-readable information from the memory leak.
CVE-2025-5777 is a critical memory leak vulnerability in NetScaler (formerly Citrix) ADC and Gateway products. It allows an unauthenticated, remote attacker to read chunks of sensitive data from the server's memory, such as session cookies, usernames, passwords, and other private information.
A successful attack resulting in a session cookie leak can lead to a full Account Takeover, completely bypassing login credentials and multi-factor authentication (MFA).
asyncio and aiohttp to scan multiple targets quickly and efficiently.NSC_AAAC).leaks.txt file for easy analysis.This tool is created for educational and authorized bug bounty purposes ONLY. Unauthorized use of this tool on any system is illegal. The developer is not responsible for any misuse or damage caused by this tool.
For a full, step-by-step guide on how to find and exploit vulnerabilities, I have created a detailed video. This video demonstrates the complete process, from identifying targets to executing the exploit.
Watch the full step-by-step video guide here: Live Hacking Demo: Finding and Exploiting a Critical Vulnerability
This project is licensed under the MIT License. See the LICENSE file for more details.