Comprehensive Vulnerability Scanner for Spring Framework
Scan-Spring-GO is a lightweight and efficient tool designed for vulnerability scanning and exploitation within the Spring ecosystem. This application supports the detection and exploitation of 17 different vulnerabilities, including critical RCE and information disclosure issues. It features built-in capabilities for detecting actuator, swagger, and druid information leaks, along with customizable dictionaries and controlled concurrency for scanning operations. Additionally, the tool integrates an MCP server that allows AI clients to automate the entire process from fingerprinting to exploitation.
The program offers dual operation modes, including a command-line interface and an MCP server for structured JSON output. It provides features such as a global rate limiter, context cancellation, and a security gate to manage target whitelisting and audit logs. The application is designed to be user-friendly, with clear command-line parameters for various scanning and exploitation tasks, ensuring stability during long runtime operations.




