> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# GraphQL Vulnerabilities

> Recursos cross-platform para GraphQL Vulnerabilities: máquinas HTB, labs PortSwigger y rooms TryHackMe curados, con writeups validados y skills relacionadas.

# GraphQL Vulnerabilities

Esta página agrega los **recursos para practicar GraphQL Vulnerabilities** de forma cross-platform: máquinas retiradas de Hack The Box, labs de PortSwigger Web Security Academy y rooms de TryHackMe, más recursos curados (HackTricks, PortSwigger, etc.) y skills relacionadas.

## Recursos curados

| Fuente      | Enlace                                                                                       |
| ----------- | -------------------------------------------------------------------------------------------- |
| PortSwigger | [https://portswigger.net/web-security/graphql](https://portswigger.net/web-security/graphql) |

## Máquinas HTB que practican GraphQL Vulnerabilities (1)

| Máquina                                            | SO    | Dificultad                                       |
| -------------------------------------------------- | ----- | ------------------------------------------------ |
| [OverGraph](/htb/machines/linux/dificil/overgraph) | Linux | <span className="dbadge dbadge-hard">HARD</span> |

## Labs PortSwigger que practican GraphQL Vulnerabilities (5)

| Lab                                                                                                          | Dificultad                                                 | Topic   | Oficial                                                                                         |
| ------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------- | ------- | ----------------------------------------------------------------------------------------------- |
| [Accessing private GraphQL posts](/portswigger/labs/graphql/graphql-reading-private-posts)                   | <span className="dbadge dbadge-easy">APPRENTICE</span>     | GraphQL | [Abrir](https://portswigger.net/web-security/graphql/lab-graphql-reading-private-posts)         |
| [Accidental exposure of private GraphQL fields](/portswigger/labs/graphql/graphql-accidental-field-exposure) | <span className="dbadge dbadge-medium">PRACTITIONER</span> | GraphQL | [Abrir](https://portswigger.net/web-security/graphql/lab-graphql-accidental-field-exposure)     |
| [Bypassing GraphQL brute force protections](/portswigger/labs/graphql/graphql-brute-force-protection-bypass) | <span className="dbadge dbadge-medium">PRACTITIONER</span> | GraphQL | [Abrir](https://portswigger.net/web-security/graphql/lab-graphql-brute-force-protection-bypass) |
| [Finding a hidden GraphQL endpoint](/portswigger/labs/graphql/graphql-find-the-endpoint)                     | <span className="dbadge dbadge-medium">PRACTITIONER</span> | GraphQL | [Abrir](https://portswigger.net/web-security/graphql/lab-graphql-find-the-endpoint)             |
| [Performing CSRF exploits over GraphQL](/portswigger/labs/graphql/graphql-csrf-via-graphql-api)              | <span className="dbadge dbadge-medium">PRACTITIONER</span> | GraphQL | [Abrir](https://portswigger.net/web-security/graphql/lab-graphql-csrf-via-graphql-api)          |

## Rooms TryHackMe que practican GraphQL Vulnerabilities (1)

| Room                                                               | Dificultad                                       | Tipo        | Acceso | Oficial                                                   |
| ------------------------------------------------------------------ | ------------------------------------------------ | ----------- | ------ | --------------------------------------------------------- |
| [Intro to GraphQL Hacking](/tryhackme/rooms/introtographqlhacking) | <span className="dbadge dbadge-easy">EASY</span> | Walkthrough | 🔵 VIP | [Abrir](https://tryhackme.com/room/introtographqlhacking) |

***

← [Volver al glosario completo](/glosario)

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"DefinedTerm","name":"GraphQL Vulnerabilities","termCode":"graphql","inLanguage":"es","url":"https://rootea.es/skills/graphql","inDefinedTermSet":{"@type":"DefinedTermSet","name":"Glosario táctico de pentesting","url":"https://rootea.es/glosario"}}`}
</script>

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"ItemList","name":"Máquinas HTB que practican GraphQL Vulnerabilities","numberOfItems":1,"itemListElement":[{"@type":"ListItem","position":1,"url":"https://rootea.es/htb/machines/linux/dificil/overgraph","name":"OverGraph"}]}`}
</script>

*Última actualización: 2026-06-07*
