GraphQL Abuse
Enumerate and attack GraphQL: schema recovery, authorization gaps, and resource abuse.
Tags: graphql, introspection, bola, dos
Level: intermediate
Method
Recover the schema
Try introspection first; if disabled, brute-force field names via suggestion errors.
clairvoyance https://target.com/graphql -o schema.json -w graphql-words.txtTools: graphql-cop, clairvoyance
Audit misconfigs
Check batching, field suggestions, CSRF (GET/urlencoded), and debug-mode error leakage.
graphql-cop -t https://target.com/graphqlTools: graphql-cop
Object/field authz (BOLA/BFLA)
Query objects by ID across tenants and call privileged mutations as a low-priv user - the top GraphQL vuln.
Tools: Burp Suite
Abuse & DoS
Test deeply nested queries, aliases, and batching for mass-assignment and resource exhaustion.
Field notes
- Aliases let you brute-force (e.g., login) hundreds of times in one request - great for rate-limit bypass.
- Mutations are where authz is most often forgotten.