NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Pwntools CTF framework and exploit development library.
Last release 11 months ago
12 Oct 2025
Ships fairly regularly
a new release about every 4 months
Nearly every release is documented
notes for 58 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
12 years old
122 releases · first in 2014
[#1044][1044] Enhancements to ROP
cyclic
context now has two additional attributes, cyclic_alphabet and cyclic_length, which correspond to the arguments alphabet and n to cyclic() and cyclic_find() and related routines.alphabet globally, so that any padding / patterns generated internally to pwntools can be controlled. The specific motivation is blacklisting values in ROP padding.QEMU_LD_PREFIX used by QEMU user-mode emulation for sysrootspwn templateCoredump.fault_addr on amd64ftp.debian.org going downOne column per quarter.
Nothing published for this version
[#1007][1007] Add support for setting a gdbinit file in the context
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
[#1043][1043] Do not attempt to populate the libraries used by statically-linked binaries
[#1038][1038] Fix an issue with process() where glibc would buffer data internally, causing a hang on select()
[#1003][1003] Make concat_all faster while also simplifying it's logic
Nothing published for this version
[#981][981] Fixed RELRO detection logic
Nothing published for this version
Nothing published for this version
[#998][998] Fix a bug where integer values could not be set in .pwn.conf.
.pwn.conf.[#933][933] DynELF works better with different base addresses
Nothing published for this version
Nothing published for this version
[#979][979]+[1a4a1e1][1a4a1e1] Fixed [#974][974], a bug related to the terminal handling and numlock.
[#895][895] Added a Dockerfile to simplify testing setup and allow testing on OSX
pwnlib.config module
~/.pwn.confpwn checksec command.pwn debug command-line utility which automates the process of gdb.attach(process(...)) to spawn GDB
pwn template command-line utility to simplify the process of bootstrapping a new exploit.
~/.pwn.confTERM_PROGRAM for run_in_new_terminalNothing published for this version
Nothing published for this version
[#945][945] Speed up ssh via caching checksec results (fixes [#944][944])
[b584ca3][b584ca3] Fixed an issue running setup.py on ARM
setup.py on ARMMemLeak
STDOUT, PIPE, PTY constants to globals
process(..., stdin=process.PTY) --> process(..., stdin=PTY)PR_SET_PTRACER for all process() and ssh.process() instances
adb modulepacking.fit() now treats large offsets as cyclic patterns (e.g. 0x61616161 behaves the same as "aaaa")ssh.checksec
execve shellcodeIKCONFIG configs from Linux kernel images, and extends checksec to report on any insecure configurations discoveredshellcraft/common and exposes them via symlinks. Closed #685
shellcraft.arch.os.syscall_function() still works the sameconnect syscall, and a TCP connect helpersh_string now returns a quoted empty string '' rather than just an empty stringprocess().corefile will automatically instantiate a Corefile for the processapport crash logsGDB's gcore scriptROP class now respects context.bytes instead of using the hard-coded value of 4 (fixed #879)process class (uid, gid, suid, sgid) which are recorded at execution time, based on the file permissionsssh.process() works internally, and it now returns a more specialized class, ssh_process.
ssh_process.corefile for fetching remote corefilesssh_process.ELF for getting an ELF of the remote executableuid, gid, and suid, and sgid which are recorded at execution time, based on the file permissionsELF.read to support contiguous memory reads across non-contiguous file-backed segmentssymlink= argument to ssh.set_working_directory, which will automatically symlink all of the files in the "old" working directory into the "new" working directoryNothing published for this version
Nothing published for this version
[#894][894] Fix a bug when using gdb.debug() over ssh.
[#800][800] Add shell= option to ssh.process()
shell= option to ssh.process()context.buffer_size for fine-tuning tube performance
buffer_fill_size= argument for all tubesprocess.leak functioncoredump_filter of all spawned processes, so that core dumps are more completeadb (unlink, mkdir, makedirs, isdir, exists)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
[#850][850] and [#846][846] fix issues with hexdump and the phd command-line utility, when using pipes (e.g. echo foo | phd)
[#843][843] fixed a bug in amd64.mov.
amd64.mov.[#840][840] fixed a regression introduced by [#837][837].
[#833][833] Fixed a performance-impacting bug in the adb module.
[b198ec8][b198ec8] Added tube.stream() function, which is like tube.interact() without a prompt or keyboard input.
tube.stream() function, which is like tube.interact() without a prompt or keyboard input.
cat file and just prints data as fast as it is received.adb.wait_for_device() re-use of the same connectionSTDERR magic argument to make logging go to stderr instead of stdout
python foo.py STDERR or PWNLIB_STDERR=1 python foo.pycontext.log_console to log to any file or terminalcyclic() when provided very large valuesglobals()-d option for hex-escaped output for shellcraft command-line toolROP.call() with Function objects from ELF.functionsadb.uptime and adb.boot_timecyclic_metasploit and cyclic_metasploit_findNothing published for this version
[#783][783] Fix adb.uninstall typo
Multiple bug fixes.
adb.uninstall typossh.process argument preexec_fnremote() when connections failedadb.partitions, which accidentally shelled out to the adb binaryCore.segments when a segment has no nameadb.wait_for_device()$HOME directory is not writableNone in MemLeak[#695][695] Fixed a performance regression in phd.
phd.run_in_terminal function, since it did not work properly in all cases.pushstr_array.pwn entry point.
asm, disasm, checksec, etc scriptspwn command (e.g. pwn asm nop).process object has a new, optional argument alarm for setting a SIGALRM timeout for processes.DynELF has a new attribute, heap, which leaks the current brk address (heap base). This is useful for finding heap allocations with dlmalloc-derived allocators like those used by Glibc.sh_string was rewritten to emit more compact and compatible strings
tubes module and the default subprocess moduleadb module now directly talks to the adb server process via a new module, adb.protocol
adbadb server vs. clientadb
install - Installs an APKuninstall - Uninstalls a packagepackages - Lists installed packagesshellcraft.sh on all platforms to provide argv[0] and set argc==1
/bin/sh which does not behave well with argc==0 or argv[0]==NULL.connect() alias for remote()
io=connect('google.com', 80)tcp(...) and udp(...) aliasesssh.read() and ssh.write() aliasesAdbDevice objects exposed via e.g. adb.devices() now offer scoped access to all adb module properties
map(lambda d: d.process(['id']).recvall(), adb.devices())Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fixed a bug in MemLeak.struct (PR: #768).
Fixed a bug in MemLeak.struct (PR: #768).
A number of smaller bugfixes and documentation tweaks.
A number of smaller bugfixes and documentation tweaks.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fixed a bug that made 3.0.3 uninstallable (Issue: #751, PR: #752)
Cherry-pick #695, as this was a regression-fix.
A small bugfix release. There were a lot of references to the master-branch, however after 3.0.0 we use the names stable, beta and dev for our branche
A small bugfix release. There were a lot of references to the master-branch, however after 3.0.0 we use the names stable, beta and dev for our branches.
This was a large release (1305 commits since 2.2.0) with a lot of bugfixes and changes. The Binjitsu project, a fork of Pwntools, was merged back into
This was a large release (1305 commits since 2.2.0) with a lot of bugfixes and changes. The Binjitsu project, a fork of Pwntools, was merged back into Pwntools. As such, its features are now available here.
As always, the best source of information on specific features is the comprehensive docs at https://pwntools.readthedocs.org.
This list of changes is non-complete, but covers all of the significant changes which were appropriately documented.
Android support via a new adb module, context.device, context.adb_host, and context.adb_port.
asm.make_elf and asm.make_elf_from_assembly.asm and shellcraft command-line tools support flags for the new shellcode encodersasm and shellcraft command-line tools support --debug flag for automatically launching GDB on the resultshellcraft moduleshellcraft moduleshellcraft module
shellcraft.<arch>.gettimeofdayshellcraft.i386.linux.)shellcraft.<arch>.linux.loadercontext.aslr which controls ASLR on launched processes. This works with both process() and ssh.process(), and can be specified per-process with the aslr= keyword argument.context.binary which automatically sets all context variables from an ELF file.context.device, context.adb, context.adb_port, and context.adb_host for connecting to Android devices.context.kernel setting for SigReturn-Oriented-Programming (SROP).context.log_file setting for sending logs to a file. This can be set with the LOG_FILE magic command-line option.context.noptrace setting for disabling actions which require ptrace support. This is useful for turning all gdb.debug and gdb.attach options into no-ops, and can be set via the NOPTRACE magic command-line option.context.proxy which hooks all connections and sends them to a SOCKS4/SOCKS5. This can be set via the PROXY magic command-line option.context.randomize to control randomization of settings like XOR keys and register ordering (default off).context.terminal for setting how to launch commands in a new terminal.DynELF().libc property which attempt to find the remote libc and download the ELF from LibcDB.DynELF().stack property which leaks the __environ pointer from libc, making it easy to leak stack addresses.MemLeak.String and MemLeak.NoNewlines and other related helpers for handling special leakers which cannot e.g. handle newlines in the leaked addresses and which leak a C string (e.g. auto-append a '\x00').MemLeak.compare to avoid leaking an entire field if we can tell from a partial leak that it does not match what we are searching for.pwnlib.encoders module for assembled-shellcode encoders/decodersCore object which can parse core-files, in order to extract / search for memory contents, and extract register states (e.g. Core('./corefile').eax).fmtstr module for assisting with Format String exploitationcontext.os=='android'gdb.debug_assembly() and gdb.debug_shellcode()pwnlib.rop.srop
SigreturnFrame() objectsprocess() has many new options, check out the documentation
aslr controls ASLRsetuid can disable the effect of setuid, allowing core dumps (useful for extracting crash state via the new Core() object)raw argumentstdout and stderr are now PTYs by default
stdin can be set to a PTY also via setting stdin=process.PTYssh objects now have a ssh.process() method which avoids the need to handle shell expansion via the old ssh.run() methoddownload and upload methods auto-detect whether the target is a file or directory and acts accordinglylisten() method alias for listen_remote()remote() method alias for connect_remote()fit() method to combine the functionality of flat() with the functionality of cyclic()negative() method to negate the value of an integer via two's complement, with respect to the current integer size (context.bytes).xor_key() method to generate an XOR key which avoids undesirable bytes over a given input.bruteforce() implementation, mbruteforce().dealarm_shell() helper to remove the effects of alarm() after you've popped a shell.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →