Initializing...

cd ..
GraphQL Private Program 2025-11-01

GraphQL Introspection Exposes Internal API Schema

Severity: Medium | Status: Resolved

Summary

The GraphQL endpoint had introspection enabled, revealing all queries, mutations, and internal admin operations.

Proof of Concept

query {
  __schema {
    types { name fields { name } }
  }
}

Impact

Full API schema disclosure including hidden admin mutations.

Responsible Disclosure

This vulnerability was reported responsibly and fixed by the vendor before public disclosure.