Escape DAST - Application Security Blog
Get a demo
  • Escape Platform
  • Case studies
  • Best Practices
  • Events
  • Community
Get a demo
Tagged

GraphQL Introspection

A collection of 2 posts

The Paradox of Disabling GraphQL Introspection: Lessons from the Parse Server GraphQL API vulnerability
GraphQL

The Paradox of Disabling GraphQL Introspection: Lessons from the Parse Server GraphQL API vulnerability

Last week, the security community was alerted to a vulnerability in Parse Server GraphQL API, which allowed public access to the GraphQL schema without requiring a session token or the master key. It is now identified as CVE-2025-53364. So, the question comes up: Should we disable introspection entirely in production

  • Antoine Carossio
Antoine Carossio Jul 17, 2025 • 4 min read
Demystifying GraphQL Security: A Comprehensive Guide to GraphQL Introspection
GraphQL Vulnerability

Demystifying GraphQL Security: A Comprehensive Guide to GraphQL Introspection

Whether or not to disable introspection in GraphQL has been a common debate among GraphQL developers since its inception. In this blog post, we will explain why completely disabling GraphQL introspection is not necessary and why it can be counterproductive. I can't really find any good reasons for

  • Antoine Carossio
Antoine Carossio Mar 30, 2023 • 5 min read
Escape DAST - Application Security Blog © 2025
  • Get a demo
  • Escape's proprietary business logic algorithm
  • Escape vs Invicti
  • Top DAST tools 2025
  • Case Studies
  • Learn how to test your GraphQL APIs
  • gRPC API Security
  • Top Qualys Alternative: Escape vs Qualys DAST
  • GraphQL Security
  • Escape vs Noname Security
  • GraphQL Armor
  • Escape Community
  • About Us
  • Privacy Policy
  • API Security Academy
  • API Gateway Security Best Practices
  • Top API security tools