GRAPHQL Injection Introspection

Identify and exploit GraphQL API vulnerabilities by leveraging Introspection queries to dump the entire database schema, performing query batching to bypass rate limits (brute forcing), and extracting deeply nested unauthorized data via graph relationship abuse.

ShulkwiSEC 4f59fc4 3 files · 17.5 KB Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/graphql-injection-introspection commit 4f59fc4a54

Frequently asked questions

npx skillmds add shulkwisec/graphql-injection-introspection