
Automated exploitation toolkit for CVE-2025-24813 targeting Apache Tomcat insecure session deserialization. Features multi-target scanning, gadget chain testing, OS detection, and post-exploitation payloads.
This is an advanced and automated exploitation tool for CVE-2025-24813, targeting Apache Tomcat servers vulnerable to insecure session deserialization.
--targets / --url)# Single target
python3 exploit_cve_2025_24813.py \
--url http://target:8080 \
--ysoserial ysoserial.jar \
--no-ssl-verify
# Multiple targets from file
python3 exploit_cve_2025_24813.py \
--targets targets.txt \
--ysoserial ysoserial.jar \
--no-ssl-verify
Python 3.6+
Java Runtime (for ysoserial)
ysoserial Java binary
This tool is provided for educational and authorized security testing purposes only. Any unauthorized use against systems you do not own or have explicit permission to test is strictly prohibited and may be illegal. 📚 Credits
This project was inspired by a public PoC published under the Apache License 2.0. Original PoC author: absholi7ly Enhanced and rewritten by mehrdad mirabi