GraphQL Vulnerability

14 posts

How we found a security misconfiguration in Philips' GraphQL API
Announcement

How we found a security misconfiguration in Philips' GraphQL API

It is a misconception that discovering vulnerabilities is only within the domain of developers and hackers. Jacob, an Account Executive at Escape, proves this notion wrong. What is a vulnerability disclosure? Vulnerability disclosure is the process of reporting security weaknesses in computer software or hardware. Individuals and groups such as
Escape - Offensive Security
Escape - Offensive Security
3 min read
What are Insecure Direct Object References (IDOR) in GraphQL, and how to fix them
GraphQL

What are Insecure Direct Object References (IDOR) in GraphQL, and how to fix them

As developers, ensuring the security of our applications is crucial. Insecure Direct Object References (IDOR) are common security vulnerabilities that occur when a system's internal implementation is exposed to users, allowing them to manipulate references to access unauthorized data. GraphQL, a powerful data query and manipulation language for
Tristan Kalos
Tristan Kalos
8 min read
GraphQL Security: Challenges & Best Practices for DApps
Web3 Security

GraphQL Security: Challenges & Best Practices for DApps

Apart from the issue of poor user experience, security is one of the greatest setbacks to global Web3. Blackhats are constantly exploiting Web3 applications to siphon funds. On the 2nd of July, 2023, Poly Network lost about $5 million to a hack. Atomic Wallet lost over $100 million to a
Escape - Offensive Security
Escape - Offensive Security
6 min read
GraphQL XSS: Cross-Site Scripting Explained
GraphQL Vulnerability

GraphQL XSS: Cross-Site Scripting Explained

Every Monday morning, you go through your ritual and check the users' feedback. This week, despite all the wonderful feedback, some users are complaining that someone has impersonated them and performed actions on their accounts without their knowledge. After some investigation, you discover that all the complaining users have
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
5 min read
Demystifying GraphQL Security: A Comprehensive Guide to GraphQL Introspection
GraphQL Vulnerability

Demystifying GraphQL Security: A Comprehensive Guide to GraphQL Introspection

Whether or not to disable introspection in GraphQL has been a common debate among GraphQL developers since its inception. In this blog post, we will explain why completely disabling GraphQL introspection is not necessary and why it can be counterproductive. I can't really find any good reasons for
Antoine Carossio
Antoine Carossio
5 min read
The 8 Most Common GraphQL Vulnerabilities (and How to Fix Them)
GraphQL Vulnerability

The 8 Most Common GraphQL Vulnerabilities (and How to Fix Them)

We at Escape have been scanning GraphQL APIs for vulnerabilities for more than two years. In this post, we will share the most common GraphQL vulnerabilities, affecting close to all GraphQL APIs we have scanned. We strongly recommend you check your GraphQL APIs for these vulnerabilities.
Gautier Ben Aïm
Gautier Ben Aïm
4 min read
GraphQL Cyclic Queries and Depth Limiting
GraphQL Vulnerability

GraphQL Cyclic Queries and Depth Limiting

The relational aspect of GraphQL can be a vulnerability exploited by running deep and cyclic queries causing your API to crawl under the load and crash. That's a Denial of Service. Learn how it works and how you can protect your API!
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
6 min read
SQL Injection in GraphQL
GraphQL Vulnerability

SQL Injection in GraphQL

You receive a call in the middle of the night from the SRE team: All production data has been deleted from your company's various relational databases. Many of the company's internal services are therefore down. You absolutely need to fix the problem immediately and identify the
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
5 min read
File Inclusion and Directory Traversal in GraphQL
GraphQL Vulnerability

File Inclusion and Directory Traversal in GraphQL

Back at the office, you try to connect to one of your application's servers. But for some reason, your account is no longer granted access. Anyway. You have a backup so you can restore it to a previous state in a minute. Still, you have to figure out
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
5 min read
When GraphQL field suggestions become a Security Issue
GraphQL Vulnerability

When GraphQL field suggestions become a Security Issue

GraphQL offers an amazing developer experience. But the same features that help you in development, can disclose critical information to cyberattacks in production. Learn how you can fix this vulnerability.
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
6 min read
How to prevent data leaks with HTTPS
GraphQL Vulnerability

How to prevent data leaks with HTTPS

HTTP is the text protocol that has been running the web, but its upgraded version HTTPS should always be preferred to avoid data leaks. Read more to understand the risk and how you can implement the security fix in your GraphQL framework of choice.
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
5 min read
Avoid GraphQL Denial of Service attacks through batching and aliasing
GraphQL Vulnerability

Avoid GraphQL Denial of Service attacks through batching and aliasing

GraphQL aliasing is a powerful feature. But with great power comes great vulnerability: batch attacks and DoS. In this post, we explain how it works and how to remediate it in your GraphQL API.
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
3 min read
Understanding and Dealing with Cross-Site Request Forgery Attacks (CSRF) in GraphQL
GraphQL Vulnerability

Understanding and Dealing with Cross-Site Request Forgery Attacks (CSRF) in GraphQL

CSRF (Cross-Site Request Forgery) is one of the top 3 most common vulnerabilities of web applications. It forces authenticated users to perform unwanted actions. In this post, we explain how it works and how to remediate it in your GraphQL API.
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
5 min read
Access Control Best Practices for GraphQL with Authentication and Authorization
GraphQL Vulnerability

Access Control Best Practices for GraphQL with Authentication and Authorization

Confusion between authentication and authorization causes data leaks. Learn the difference and how to implement the right access control pattern in your GraphQL API.
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
6 min read