Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Accessing private GraphQL posts (Apprentice) · 🇬🇧
- TryHackMe — Intro to GraphQL Hacking (Easy · ~30 min) · 🇬🇧
- PortSwigger — Accidental exposure of private GraphQL fields (Practitioner) · 🇬🇧
- PortSwigger — Bypassing GraphQL brute force protections (Practitioner) · 🇬🇧
- PortSwigger — Finding a hidden GraphQL endpoint (Practitioner) · 🇬🇧
- PortSwigger — Performing CSRF exploits over GraphQL (Practitioner) · 🇬🇧
Curated resources
HTB machines practicing GraphQL Vulnerabilities (1)
PortSwigger labs practicing GraphQL Vulnerabilities (5)
TryHackMe rooms practicing GraphQL Vulnerabilities (1)
← Back to the full glossary Last updated: 2026-08-13