GraphQL Private Program 2025-11-01
GraphQL Introspection Exposes Internal API Schema
Severity: Medium | Status: Resolved
Summary
The GraphQL endpoint had introspection enabled, revealing all queries, mutations, and internal admin operations.
Proof of Concept
query {
__schema {
types { name fields { name } }
}
}
Impact
Full API schema disclosure including hidden admin mutations.
Responsible Disclosure
This vulnerability was reported responsibly and fixed by the vendor before public disclosure.