recon-ng
Install command:
brew install recon-ngWeb Reconnaissance Framework
https://github.com/lanmaster53/recon-ng
License: GPL-3.0-only
Development: Pull requests
Formula JSON API: /api/formula/recon-ng.json
Formula code: recon-ng.rb on GitHub
Bottle (binary package) installation support provided for:
| macOS on Apple Silicon |
tahoe | ✅ |
|---|---|---|
| sequoia | ✅ | |
| sonoma | ✅ | |
| macOS on Intel |
sonoma | ✅ |
| Linux | ARM64 | ✅ |
| x86_64 | ✅ | |
Current versions:
| stable | ✅ | 5.1.2 |
Revision: 3
Depends on:
| certifi | 2026.7.22 | Mozilla CA bundle for Python |
| libyaml | 0.2.5 | YAML Parser |
| python@3.14 | 3.14.7 | Interpreted, interactive, object-oriented programming language |
| rpds-py | 2026.6.3 | Python bindings to Rust's persistent data structures |
Known vulnerabilities in the current version:
| GHSA-38jv-5279-wg99 (high) | Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) |
| GHSA-87hc-h4r5-73f7 (medium) | Werkzeug safe_join() allows Windows special device names with compound extensions |
| GHSA-gc5v-m9x4-r6x2 (medium) | Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function |
| GHSA-29vq-49wr-vm6x | Werkzeug safe_join() allows Windows special device names |
| GHSA-68rp-wp8r-4726 | Flask session does not add `Vary: Cookie` header when accessed in some ways |
| GHSA-8mp2-v27r-99xp | Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input |
| GHSA-vfmq-68hx-4jfw (high) | lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files |
| GHSA-qccp-gfcp-xxvc (medium) | urllib3: Sensitive headers forwarded across origins in proxied low-level redirects |
| GHSA-mf9v-mfxr-j63j (high) | urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API |
| GHSA-8g87-j6q8-g93x (medium) | Mistune Math Plugin has an XSS Escape Bypass |
| GHSA-58cw-g322-p94v (medium) | Mistune has XSS via unescaped figclass/figwidth in Figure directive |
| GHSA-v87v-83h2-53w7 (medium) | Mistune Heading ID Attribute has Injection XSS |
| GHSA-6269-cqxg-mhhv (medium) | Mistune TOC Anchor Injection XSS |
| GHSA-ccfx-mfmx-2fx9 (medium) | Mistune Image Directive CSS Injection Vulnerability |
| GHSA-65pc-fj4g-8rjx (medium) | Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() ... |
| GHSA-qcq2-496w-v96p (high) | Mistune: Potential DoS via quadratic-time parsing in parse_link_text |
| GHSA-c8j7-8cv4-2xmq (high) | Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` ... |
| GHSA-8c25-4j27-2rv3 (medium) | Mistune: XSS via percent-encoded javascript URI bypass in safe_url() |
| GHSA-r4rv-85jg-w4mf (medium) | Mistune: Arbitrary File Read via Include directive path traversal |
| GHSA-4j32-57v6-6g45 (high) | Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs |
| GHSA-g97x-gvcm-x72h | Mistune: XSS via unescaped class option in Admonition directive |
| GHSA-8mpj-m6qm-5qr8 (medium) | Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionE... |
| GHSA-ffq3-xpv3-j92q (high) | Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions |
| GHSA-qfrw-5rxm-mhh2 (medium) | Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that hi... |
| GHSA-2hm2-hc3v-44h9 (medium) | Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no sl... |
| PYSEC-2026-2132 (high) |
Data from Homebrew/advisory-database. Run brew vulns recon-ng for a live check.
Analytics:
| 30 days | 90 days | 365 days | |
|---|---|---|---|
| Installs | 48 | 169 | 1,026 |
| Installs on Request | 48 | 169 | 1,026 |
| Build Errors | 1 |