vulns.co
/
GKData.io MCP

Back to Playbooks

GraphQL Abuse

Enumerate and attack GraphQL: schema recovery, authorization gaps, and resource abuse.

Tags: graphql, introspection, bola, dos

Level: intermediate

Method

  1. Recover the schema

    Try introspection first; if disabled, brute-force field names via suggestion errors.

    clairvoyance https://target.com/graphql -o schema.json -w graphql-words.txt

    Tools: graphql-cop, clairvoyance

  2. Audit misconfigs

    Check batching, field suggestions, CSRF (GET/urlencoded), and debug-mode error leakage.

    graphql-cop -t https://target.com/graphql

    Tools: graphql-cop

  3. Object/field authz (BOLA/BFLA)

    Query objects by ID across tenants and call privileged mutations as a low-priv user - the top GraphQL vuln.

    Tools: Burp Suite

  4. Abuse & DoS

    Test deeply nested queries, aliases, and batching for mass-assignment and resource exhaustion.

Field notes

  • Aliases let you brute-force (e.g., login) hundreds of times in one request - great for rate-limit bypass.
  • Mutations are where authz is most often forgotten.

References