Back to Skills

jndi-injection

JNDI injection playbook. Use when Java applications perform JNDI lookups with attacker-controlled names, especially via Log4j2, Spring, or any code path reaching InitialContext.lookup().

1,297stars177forksUpdated 7/7/2026

Security Assessment

Low Risk(75/100)

Detected risks:

Remote Code Execution([SKILL.md] exec()
Security Score75/100

About jndi-injection

A security-testing playbook for JNDI injection, the vulnerability class in which a Java application performs a naming lookup on attacker-controlled input and is coerced into loading or executing remote code. It is meant for situations where code reaches InitialContext.lookup with untrusted data, especially through Log4j2, Spring, or similar sinks, and it clarifies how JNDI injection differs from generic deserialization.

It walks through the core mechanism and the main attack vectors: RMI and LDAP for class loading, and DNS for detection-only confirmation. A JDK version table explains how mitigations added in 8u121 and 8u191 constrain remote class loading and which bypasses remain, including returning a serialized gadget object over LDAP when a gadget chain is on the classpath, and abusing Tomcat BeanFactory with expression-language evaluation. Tooling coverage includes marshalsec reference servers, JNDI-Injection-Exploit, and RogueJndi.

A dedicated section covers Log4Shell (CVE-2021-44228): how Log4j2 lookups evaluate a jndi expression inside any logged string, detection payloads, injection points such as headers and form fields, WAF-bypass obfuscation variants, a split-log bypass, and affected versions from 2.0-beta9 through 2.14.1 with full fixes in 2.17.0 and Log4j 1.x unaffected. It also lists other JNDI sinks across Spring, Solr, Druid, vCenter, H2, and Fastjson, and provides a testing methodology that starts with a safe DNS probe to confirm evaluation before escalating based on the JDK version. Use it to identify, confirm, and safely demonstrate JNDI injection during application security testing.

FAQ

When should I use this skill?

When a Java application performs JNDI lookups on attacker-controlled names, especially via Log4j2, Spring, or any path reaching InitialContext.lookup.

What attack vectors does it cover?

RMI and LDAP for remote class loading and DNS for detection only; LDAP is preferred because its restrictions were added later than RMI.

How does the JDK version affect exploitation?

Versions before 8u121 allow direct remote class loading, 8u121 to 8u190 need the LDAP vector, and 8u191 and later require a serialized gadget or the BeanFactory plus expression-language bypass.

What is Log4Shell?

CVE-2021-44228, where Log4j2 evaluates a jndi lookup inside any logged string; it affects versions 2.0-beta9 through 2.14.1, is fully fixed in 2.17.0, and does not affect Log4j 1.x.

How can you confirm JNDI injection without achieving code execution?

Send a DNS-only probe, such as a jndi dns lookup to a controlled token host; a DNS hit confirms the lookup was evaluated.

Install jndi-injection

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill