GraphQL
29 posts
GraphQL
The Paradox of Disabling GraphQL Introspection: Lessons from the Parse Server GraphQL API vulnerability
Last week, the security community was alerted to a vulnerability in Parse Server GraphQL API, which allowed public access to the GraphQL schema without requiring a session token or the master key. It is now identified as CVE-2025-53364.
So, the question comes up: Should we disable introspection entirely in production
GraphQL Security
How to secure GraphQL APIs: challenges and best practices
GraphQL APIs, while offering robust features and flexibility, present unique security challenges compared to traditional REST APIs. This article delves into the complexities of securing GraphQL APIs, highlighting common vulnerabilities and providing a comprehensive guide to best practices for building secure GraphQL apps.
A visual learner? Check out our latest
Announcement
How we found a security misconfiguration in Philips' GraphQL API
It is a misconception that discovering vulnerabilities is only within the domain of developers and hackers. Jacob, an Account Executive at Escape, proves this notion wrong.
What is a vulnerability disclosure?
Vulnerability disclosure is the process of reporting security weaknesses in computer software or hardware. Individuals and groups such as
Announcement
Escape and Xolvio officially partner to help teams secure their GraphQL APIs!
Keeping APIs secure is vital. However, not all organizations have the in-house resources to tackle it effectively. Xolvio's clients can now leverage Escape's expertise in GraphQL security and performance assessments. They can also integrate it into their CI/CD pipelines, enhancing their API security
GraphQL
What are Insecure Direct Object References (IDOR) in GraphQL, and how to fix them
As developers, ensuring the security of our applications is crucial. Insecure Direct Object References (IDOR) are common security vulnerabilities that occur when a system's internal implementation is exposed to users, allowing them to manipulate references to access unauthorized data. GraphQL, a powerful data query and manipulation language for
API Security
API Security Academy: How It Works Under the Hood
The API Security Academy is built upon a technology that comes straight from the future—and by that, we mean the brilliant minds at StackBlitz - WebContainers. You may already know regular containers, the ones you can run with Docker and Kubernetes, which are lightweight virtualization units that allow developers
GraphQL
API Security Academy: a smarter way to learn GraphQL security
Learning about GraphQL security is now more accessible than ever! We're excited to introduce the API Security Academy, developed by the Escape team.
Escape's API Security Academy is a free and open-source collection of interactive challenges that will teach you how to secure your GraphQL applications.
Web3 Security
GraphQL Security: Challenges & Best Practices for DApps
Apart from the issue of poor user experience, security is one of the greatest setbacks to global Web3. Blackhats are constantly exploiting Web3 applications to siphon funds. On the 2nd of July, 2023, Poly Network lost about $5 million to a hack. Atomic Wallet lost over $100 million to a
GraphQL
GraphQL Wordlist: Free Open Source for Penetration Testing
In cybersecurity, the old saying that the "best defense is a good offense" rings true. This philosophy is reflected in the approach we call offensive security. It involves actively seeking out system vulnerabilities to fix them before they can be exploited. It's about taking the initiative,
GraphQL
Goctopus: Open Source GraphQL Discovery & Fingerprinting
In the fast-evolving domain of APIs, GraphQL has emerged as a powerful, data-oriented language. As its adoption soars, so does the need for robust tools to discover and fingerprint these APIs. Enter Goctopus, a Golang-based solution we developed at Escape to provide comprehensive, fast, and interoperable endpoint discovery and fingerprinting
Announcement
Escape raises $3.9 million in seed to secure APIs at every development stage
Official Press release
* Six months after releasing its API security platform, Escape has already secured the applications of 1000+ organizations worldwide and just graduated from Y Combinator.
* The funding will allow the company to hire new team members covering European and US-based customers, aiming to double the team’s size
GraphQL
Introducing Seamless GraphQL Compliance
As your go-to partner in GraphQL Security, we at Escape are constantly innovating to simplify and streamline security for you. We're proud of our reputation for crafting modern, dynamic application security testing (DAST) tools tailored to GraphQL, beloved by developers and trusted by security teams worldwide. From comprehensive
GraphQL Vulnerability
GraphQL XSS: Cross-Site Scripting Explained
Every Monday morning, you go through your ritual and check the users' feedback. This week, despite all the wonderful feedback, some users are complaining that someone has impersonated them and performed actions on their accounts without their knowledge.
After some investigation, you discover that all the complaining users have
GraphQL
GraphQL Input Validation & Sanitization
Why input validation and sanitization are important in GraphQL?
GraphQL allows you to identify the data and validate inputs based on type information. By default, GraphQL Specification has the Int, Float, String, Boolean and ID Scalar types. But as a conscious API developer, you've probably come across situations
GraphQL
Top 5 GraphQL vulnerabilities burdening HIPAA compliance
TL;DR: GraphQL vulnerabilities will inevitably burden organizations, especially when healthcare compliances like HIPAA come into play. This article highlights how Escape makes it super easy to release compliant APIs.
The correlation between HIPAA and GraphQL is that PHI resources can be exposed through GraphQL APIs, allowing for a more
Postman
Find & Fix GraphQL API Security Issues with Postman
Improve the security of your GraphQL API with Escape and Postman
Are you tired of dealing with pesky API vulnerabilities? Want to take your GraphQL game to the next level? Introducing the perfect combo for GraphQL success - Escape and Postman.
Escape is a tool that helps developers automatically and
Pentesting
GraphQL Pentesting: Thinking Outside the Box
The hardest part when pentesting any system is undoubtedly answering the question:
💡How should we think of that?
What is meant is "how outside-the-box thinking works?", and "how is a pentester meant to think outside the box?".
Although tackling this question might seem like a near
GraphQL
GraphQL Security: How to Prevent Data Breaches
Manage your sensitive data in GraphQL applications (PII, passwords, secrets…)
We released a new feature in Escape that enables you to detect and fix data leaks with GraphQL.
🚫 The GraphQL Access Control issue, what is it?
Access control is the restriction that tells the user who or what can be