commixproject/commix

Automated exploitation of command injection vulnerabilities. From detection to full control of the underlying operating system.

5,838

stars

2,436

commits

Python

primary language

Sep 11, 2026

updated

commixproject.com
bugbounty
command-injection
commix
detection
exploitation
open-source
pentesting
python
takeover
vulnerability-scanner

README

CommixProject

Builds Tests Python 2.6|2.7|3.x GPLv3 License GitHub closed issues X

Commix (short for [comm]and [i]njection e[x]ploiter) is an open source penetration testing tool, written by Anastasios Stasinopoulos (@ancst), that automates the detection and exploitation of command injection vulnerabilities.

Screenshot

You can visit the collection of screenshots demonstrating some of the features on the wiki.

Installation

You can download commix on any platform by cloning the official Git repository :

$ git clone https://github.com/commixproject/commix.git commix

Alternatively, you can download the latest tarball or zipball.

Note: Python (version 2.6, 2.7 or 3.x) is required for running commix.

Usage

To get a list of all options and switches use:

$ python commix.py -h

To get an overview of commix available options, switches and/or basic ideas on how to use commix, check usage, usage examples and filters bypasses wiki pages.

Translations

Contributors

stasinopoulos

2,406 commits

apprentice

9 commits

dnet

3 commits

g0tmi1k

2 commits

commixproject/commix

Automated exploitation of command injection vulnerabilities. From detection to full control of the underlying operating system.

5,838

stars

2,436

commits

Python

primary language

Sep 11, 2026

updated

commixproject.com
bugbounty
command-injection
commix
detection
exploitation
open-source
pentesting
python
takeover
vulnerability-scanner

README

CommixProject

Builds Tests Python 2.6|2.7|3.x GPLv3 License GitHub closed issues X

Commix (short for [comm]and [i]njection e[x]ploiter) is an open source penetration testing tool, written by Anastasios Stasinopoulos (@ancst), that automates the detection and exploitation of command injection vulnerabilities.

Screenshot

You can visit the collection of screenshots demonstrating some of the features on the wiki.

Installation

You can download commix on any platform by cloning the official Git repository :

$ git clone https://github.com/commixproject/commix.git commix

Alternatively, you can download the latest tarball or zipball.

Note: Python (version 2.6, 2.7 or 3.x) is required for running commix.

Usage

To get a list of all options and switches use:

$ python commix.py -h

To get an overview of commix available options, switches and/or basic ideas on how to use commix, check usage, usage examples and filters bypasses wiki pages.

Translations

Contributors

stasinopoulos

2,406 commits

apprentice

9 commits

dnet

3 commits

g0tmi1k

2 commits

Languages

Python

100.0%