Maintenance in progress: we are indexing a large batch of new skills. Some pages may load slowly or briefly show no results. Nothing is lost, and everything is back to normal within the hour.

GRAPHQL Introspection Abuse

Exploit exposed GraphQL introspection endpoints to map the entire API schema. This skill details how to extract available queries, mutations, types, and fields, which significantly aids in identifying hidden endpoints, Broken Object Level Authorization (BOLA/IDOR), and mass assignment vulnerabilities.

ShulkwiSEC 272fa7d 3 files · 13.7 KB Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/graphql-introspection-abuse commit 272fa7da7d

Frequently asked questions

npx skillmds add shulkwisec/graphql-introspection-abuse