vulns.co
/
GKData.io MCP

Coverage by class

Generated from the hunt records. None yet means the catalog does not have that link. It is not a claim that the class is unimportant.

ClassSkillChecklistDisclosureAcademy
SSRF huntingNone yetSSRFNone yetAcademy
XSS huntingJavaScript and client trustJavaScript review, XSS1 on the briefAcademy
IDOR and broken authorizationAccess control and tenant boundariesAuthorization / IDOR2 on the briefAcademy
JWT attacksSession, cookies, and passkeysJWT / session tokensNone yetAcademy
OAuth and OIDCOAuth, DPoP, and mix-upModern OAuth and OIDCNone yetAcademy
GraphQL huntingGraphQL APIsGraphQL1 on the briefAcademy
Web cache poisoningCache deception and cache poisoningCacheNone yetAcademy
CSRF huntingNone yetNone yet1 on the briefAcademy
SQL injection huntingNone yetSQL injection2 on the briefAcademy
XXE huntingNone yetNone yetNone yetAcademy
SSTI huntingNone yetNone yetNone yetAcademy
LFI to impactNone yetNone yetNone yetAcademy
CORS exploitationNone yetNone yetNone yetAcademy
WebSocket huntingNone yetWebSocketsNone yetAcademy
Race conditionsNone yetRace / TOCTOUNone yetAcademy
HTTP request smugglingNone yetNone yetNone yetAcademy
SAML attacksNone yetNone yetNone yetNone yet
MFA / 2FA bypassSession, cookies, and passkeysAuthentication / ATO, Passkeys and WebAuthn1 on the briefAcademy
File upload huntingNone yetNone yet1 on the briefAcademy
Agents, tools, and retrievalAgents, MCP, and retrievalMCP and agent tools, RAG retrieval boundariesNone yetAcademy
Open redirect chainsNone yetNone yetNone yetNone yet
postMessage gadgetsJavaScript and client trustJavaScript reviewNone yetAcademy
Passkey and WebAuthnSession, cookies, and passkeysPasskeys and WebAuthn1 on the briefNone yet
Tenant boundariesAccess control and tenant boundariesTenant isolationNone yetAcademy
Web cache deceptionCache deception and cache poisoningCache deceptionNone yetAcademy
Session and cookie scopeSession, cookies, and passkeysSession cookie inventory, Authentication / ATONone yetAcademy
Supply chain and CICI and dependency trustDependency and CI supply chain1 on the briefNone yet
MCP and tool trustAgents, MCP, and retrievalMCP and agent toolsNone yetNone yet
RAG retrieval boundariesAgents, MCP, and retrievalRAG retrieval boundariesNone yetNone yet
Mobile app linksMobile links and API hostsMobile links and app association1 on the briefNone yet
Parsers and archivesParsers, archives, and fail-openParser differentials, Exception and debug paths1 on the briefNone yet
Security misconfigurationNone yetNone yetNone yetNone yet
Webhook authenticityAccess control and tenant boundariesExports and webhooksNone yetNone yet
Email identityNone yetNone yetNone yetNone yet
Business logicNone yetNone yetNone yetAcademy
Subdomain takeoverNone yetNone yetNone yetNone yet
Prototype pollutionNone yetNone yetNone yetAcademy
Mass assignmentAccess control and tenant boundariesNone yetNone yetAcademy
Reset and magic linksSession, cookies, and passkeysNone yetNone yetAcademy
ClickjackingNone yetNone yetNone yetAcademy
Cloud object storageCloud object storageCloud / SaaS extrasNone yetNone yet
Provisioning and invitesProvisioning and invitesNone yetNone yetNone yet
Billing and creditsBilling and creditsNone yetNone yetAcademy

Academy links are PortSwigger Web Security Academy topic pages. The lab stays on their site. A class with no public card still says so on its hunt brief.