Submit your favorite resources for free.

Submit
HackDB logoHackDB
icon of GraphQLmap

GraphQLmap

GraphQLmap is a scripting engine for GraphQL endpoint pentesting, automating queries and fuzzing for vulnerabilities.

Introduction

GraphQLmap

GraphQLmap is a scripting engine designed for penetration testing GraphQL endpoints. It automates interaction, schema dumping, and fuzzing to uncover vulnerabilities.

Key features:

  • Schema Dumping: Automatically extracts GraphQL schema for analysis.
  • Query Execution: Enables direct interaction with GraphQL endpoints using custom queries.
  • Field Fuzzing: Supports bruteforcing and iterating over GraphQL parameters to identify potential weaknesses.
  • Injection Testing: Facilitates NoSQL and SQL injection attempts within GraphQL fields.
  • Batching: Supports GraphQL batching to send multiple queries in a single request.

Use cases:

  • Security audits of GraphQL APIs.
  • Bug bounty hunting on platforms using GraphQL.
  • Penetration testing engagements targeting GraphQL implementations.

Information

  • Publisher
  • Websitegithub.com
  • Created date06/02/2025
  • Published date06/02/2025

Tags

215+ Subscribers
Newsletter

Join 215+ Professionals

Receive our monthly newsletter featuring the latest additions to the directory.

No spam. Unsubscribe anytime.