Explore tweets tagged as #Graphql
Parsed 12k+ bug-bounty write-ups & blogs (and counting 24/7) and mapped each to CWE + language. Quick hits:.• ~60% of RCEs happen in PHP/JS.• >50% of GraphQL bugs are plain access-control issues. Free site coming soon - reply "access" for an early invite! #bugbounty #hacking
150
22
237
🧠 GraphQL Introspection + Injection.1️⃣ Introspection enabled → attacker maps full schema.2️⃣ Finds sensitive queries/mutations.3️⃣ Sends crafted input to vulnerable resolver.4️⃣ Possible SQLi, IDOR, or RCE in backend.🎯 Schema leak → attack blueprint.#bugbounty #graphql
3
15
89
Sometimes you get good bounties even without “bug-bounty”. Tip: Never skip GraphQL functionalities, In my cade without even logging in to web app, I was able to Dump PII (Limited disclosure) but still without any authentication. CC: @ThisIsDK999 . #BugBounty #bugbountytips
8
5
130
Still can’t mint new items on Opensea. The GraphQL error is ongoing. This is exactly how I feel: 🫠. @opensea @opensea_support
1
0
1
See why I’m calling it unstoppable. This video dives into what makes Nitro GraphQL a game-changer — hot reload, auto-typing, tons of new features…. I’m spinning up a GraphQL server to see for myself. Could this be the best thing that’s ever happened to GraphQL?
It’s here. Add nitro-graphql to your app and witness not just Nitro, but GraphQL itself level up—auto-typed, hot-reloaded, and unstoppable. ⚡️ Feel the power:
0
1
10
zkgm . Just spotted that @union_build added a new API section in their docs 👀. If you’re building something cool with onchain data, it’s worth checking out.
17
8
19
Vibe coded a Shopify menu migrator: .. Uses Storefront API to grab menus; uses Admin GraphQL API to write menus. Used @claudeai as the brains, tested as my IDE.
3
0
5
zkgm. just noticed @union_build added new API tab in their docs👀. If anyone’s looking to build something cool with onchain data go check it out.
59
4
144
Always check GraphQL requests don't rely on UI, the REMOVE option for super admin user was not shown on the UI of website, however the admin is able to remove the user via GraphQL request. #BugBounty
0
2
85