
mantra
「🔑」A tool used to hunt down API key leaks in JS files and pages

「🔑」A tool used to hunt down API key leaks in JS files and pages

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

CVE-2025-55182(React Server Components 反序列化远程代码执行漏洞)

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

Electron JS Browser To Find XSS Vulnerabilities Automatically

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

CVE-2018-6389 PoC node js multisite with proxy