If you find a security issue in SPRecon, please report it privately rather than opening a public issue. Email bilal+SPRecon@zer0byte.com, or open a GitHub private security advisory. I aim to acknowledge reports within 72 hours.
SPRecon is a read-only reconnaissance tool for authorized security assessments of SharePoint Online and Microsoft 365. It is designed not to write, share, grant, upload, or delete anything. The transport issues GET only, with a single path gated to the read-only Search API. There is no code path that creates a sharing link, changes permissions, adds a guest, or uploads a file.
Reports are welcome on any of the following:
- A way the read-only guarantee could be violated.
- False positives or false negatives in detection. The
ViewableByExternalUserssearch property in particular reflects external-sharing capability for an item's location, not proof of an active share, and SPRecon reports it as a lead to verify rather than confirmed exposure. - Detection accuracy for secrets, PII, sensitive-named documents, or broad-access grants.
SPRecon can surface credentials and PII that exist in a tenant. It masks credit card and Social Security numbers everywhere, including the exported report, so full values never land in a deliverable. Operators are expected to handle all findings under the engagement's data-handling rules and to confirm the tenant is in scope before running the tool.