Fixed cross-platform binary path resolution using the which crate for improved compatibility across operating systems.
Release history
Lonkero releases
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.
All releases
23 shown
Fixed UTF-8 boundary panic crashes when processing multi-byte characters, improving stability with international text.
Fixed broken XSS and framework scanners, CMS scan handler, UTF-8 string slicing panics, browser extension CSP violations, and license validation issues.
- WAF Bypass button with 220+ techniques
- AI-powered security testing agent
- Scanner functionality
- Improved findings display
- HMAC authentication vulnerability
- SSRF (Server-Side Request Forgery) vulnerability
- Temp-directory security issues
- Token detection enhancements
- JS route and API extraction with probing
- Next.js vulnerability detection
- Browser extension now requires Personal+ license tier
- CSP (Content Security Policy) bypass fixes
- License gating for browser extension
Fixed unclosed character class in sandbox detection regex pattern that affected pattern matching reliability.
- Replaced federated learning with one-way model distribution API
- Security vulnerabilities fixed
- One-way model distribution API
- README.md invisible prompt injection scanner
Version merge integrating 3.9.0 changes into release branch.
Fixed scanner freeze issue, disabled aggressive anti-tamper checks blocking Professional license tier users, and updated dependencies.
Fixed scanner freeze on b61 nx architecture affecting scanning performance.
Fixed scanner freeze issue on b61 nx architecture affecting scanning performance.
Prevented scanner freeze by removing parallel iteration in browser extension scanner implementation.
Multiple dependency updates including serde_json, rust_xlsxwriter, deadpool-redis, blake3, and flate2. Removed unused dependencies and fixed compiler compatibility issues.
- SQLi confirmation techniques in OOBZero
- 404 response filtering
Removed incorrect skip logic for Node.js command injection detection that was preventing legitimate vulnerability detection.
- Security vulnerabilities from review fixed
Improved CI/CD infrastructure with cross-platform build fixes for ARM and macOS, updated GitHub Actions, enabled crates.io publishing, and improved Chrome compatibility in CI environments.
- Strict signing with no offline fallback
- Quantum-safe report signing
- CVE-2025-55183/55184 detection
- Google Dorking module