You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ETHICAL USE ONLY – AUTHORIZED SECURITY TESTING
This repository provides tools for authorized security professionals, blue teams, and penetration testers only.
Unauthorized access to computer systems is illegal under CFAA (US), Computer Misuse Act (UK), TCK 243/244 (Turkey), and similar laws worldwide.
📖 Vulnerability Overview
CVE‑2026‑82329 is a critical authentication bypass vulnerability in self-hosted JFrog Artifactory (versions 7.111.x through 7.161.x) that allows an unauthenticated attacker to obtain a full platform administrator token by abusing the JFrog Access cluster join mechanism.
How it works
Blank join key trust – JFrog Access trusts a phantom join key whose value is an empty string. Its signing secret is therefore the deterministic value 32 * 0x20 (spaces).
Forged join JWT – an attacker forges an HS256 JWT signed with this known secret and kid = SHA256("").
SERVICE token issued – POST /access/api/v1/registry/join returns a SERVICE token with scp=admin without any authentication.
Admin token exchange – POST /access/api/v1/tokens with scope=applied-permissions/admin&audience=* yields a full platform admin token.
Impact – full repository takeover, token theft, admin user creation, artifact poisoning, supply-chain attacks, and lateral movement into connected services (Xray, Mission Control, Distribution). Upgrade immediately!
Affected Versions
7.111.4 – 7.111.20 – vulnerable
7.117.0 – 7.117.27 – vulnerable
7.125.0 – 7.125.19 – vulnerable
7.133.0 – 7.133.28 – vulnerable
7.146.0 – 7.146.36 – vulnerable
7.161.0 – 7.161.19 – vulnerable
Patch
Upgrade to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20 or newer.
If upgrade is not possible, restrict network access to Artifactory (never expose it to the internet) and rotate all admin tokens as a temporary workaround.
🧰 Tools
Tool
Purpose
Intended User
exploit.py
Full weaponized toolkit with JWT forging, admin token exchange, admin user creation, mass scanning, stealth mode, proxy rotation, interactive menu, and full attack chain.
Red teams / authorized pentesters
safechecker.py
Non‑intrusive vulnerability checker that detects Artifactory version, validates exposure, and assesses risk without obtaining any token or executing any payload. Generates JSON reports.
Blue teams / security auditors
📊 Feature Comparison
Feature
exploit.py
safechecker.py
Vulnerability detection
✅
✅
Version detection
✅
✅
Forged join JWT
✅
❌
Service token mint
✅
❌
Admin token exchange
✅
❌
Admin user creation
✅
❌
List repositories
✅
❌
List users
✅
❌
Dump configuration
✅
❌
Dump tokens
✅
❌
Full attack chain
✅
❌
Interactive menu
✅
❌
Mass scanning (multi‑thread)
✅
✅
Proxy support
✅
✅
Proxy rotation
✅
❌
Tor support (anonymity)
✅
❌
User‑Agent rotation (OPSEC)
✅
❌
Jitter (OPSEC)
✅
❌
Adaptive rate limiter
✅
❌
Non‑intrusive (safe) mode
❌
✅
Version report
✅
✅
Anonymous access check
❌
✅
JSON report
✅
✅
Log cleanup (anti‑forensic)
✅
❌
Custom User‑Agent
✅
✅
SSL verification control
✅
✅
🎯 Use Case Summary
Scenario
Recommended Tool
Blue Team – verifying if your Artifactory is vulnerable