Skip to main content

vamp-graphql-audit

Python 3.11+ Platform aiohttp VampSecure Labs

Overview

vamp-graphql-audit is a DAST (Dynamic Application Security Testing) tool specialized in GraphQL APIs. It performs six sequential audit phases covering the most critical GraphQL-specific attack vectors: introspection abuse, broken object-level authorization (BOLA/IDOR), rate-limit bypass via alias abuse, deep nesting DoS, information disclosure via field suggestions, injection testing (SQLi, NoSQLi, SSTI, XSS), and subscription/mutation security analysis.

It generates professional reports in rich console output, JSON, and a self-contained HTML dark-theme document — ready to attach to a pentest engagement.

Features

  • Phase 1 — Introspection & Recon: detects enabled introspection (CRITICAL), extracts full schema (queries, mutations, subscriptions, types), identifies sensitive field names (password, token, key, email…), checks for verbose error messages with stack traces or file paths, and fingerprints directives to identify framework.
  • Phase 2 — Authorization Testing (BOLA/IDOR): fuzzes ID arguments (1, 2, 3, 999, -1, "admin", null…) on every query with an ID-shaped argument; flags CRITICAL when different IDs return non-null data without apparent ownership checks.
  • Phase 3 — Rate Limiting & DoS: alias abuse with 100 aliases in one HTTP request (HIGH), deeply-nested query with configurable --depth (HIGH if > 5s or timeout), batch query abuse via JSON array payload (HIGH).
  • Phase 4 — Information Disclosure: confirms active GraphQL endpoint via __typename, detects field suggestions that leak schema even with introspection disabled (MEDIUM), checks for verbose variable-error messages, inspects non-standard directives.
  • Phase 5 — Injection Testing: SQL injection via error-response analysis, NoSQL operator injection via GraphQL variables, SSTI detection by evaluating {{7*7}} markers in response, Reflected XSS via GraphQL string arguments.
  • Phase 6 — Subscription & Mutation Security: HTTP vs HTTPS check, subscription authentication advisory, rate-limiting absence on auth mutations (login, register…), credential-change mutations without current-password confirmation, token return types over unencrypted HTTP.

Requirements

  • Python 3.11 or later
  • aiohttp >= 3.9.0
  • rich >= 13.7.0
pip install -r requirements.txt

Usage

# Auditoría básica
python3 vamp_graphql_audit.py --target https://api.ejemplo.com/graphql

# Con cabecera de autenticación
python3 vamp_graphql_audit.py \
  --target https://api.ejemplo.com/graphql \
  --header "Authorization: Bearer eyJhbGc..."

# Múltiples cabeceras + exportar informe
python3 vamp_graphql_audit.py \
  --target https://api.ejemplo.com/graphql \
  --header "Authorization: Bearer TOKEN" \
  --header "X-Tenant-Id: acme" \
  --json informe.json \
  --html informe.html

# Controlar profundidad del test DoS de nesting
python3 vamp_graphql_audit.py \
  --target https://api.ejemplo.com/graphql \
  --depth 12

# Timeout por petición en segundos (default: 30)
python3 vamp_graphql_audit.py \
  --target https://api.ejemplo.com/graphql \
  --timeout 60

Exit Codes

Code Significado
0 Auditoría limpia — sin hallazgos CRITICAL ni HIGH
1 Al menos un hallazgo CRITICAL o HIGH
2 Error de ejecución (red, parámetros inválidos, interrupción)

Output

  • Console: banner ASCII + progreso en tiempo real por fase + tabla resumen de findings ordenados por severidad.
  • JSON (--json FILE): objeto con metadata, resumen por severidad, schema descubierto y array completo de findings.
  • HTML (--html FILE): informe auto-contenido dark-theme con resumen ejecutivo, tabla de findings con evidencias expandibles y panel del schema descubierto.

Disclaimer

Esta herramienta es exclusiva para auditorías de seguridad autorizadas. El uso contra sistemas sin autorización escrita del propietario es ilegal. VampSecure Studios no asume responsabilidad por usos indebidos.

Metadata

Release files for vamp-graphql-audit 1.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-graphql-audit 1.3.0
File Size Uploaded
vamp_graphql_audit-1.3.0.tar.gz 31.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-graphql-audit 1.3.0
File Interpreter ABI Platform
vamp_graphql_audit-1.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 63.9 kB

Release files / vamp_graphql_audit-1.3.0.tar.gz

Download URL vamp_graphql_audit-1.3.0.tar.gz
Size 31.5 kB
Tags Source
SHA-256 checksum
How to use checksums
70f92791899396fdfd30f60f5c5276b783cefbe8326e051850691cf010c81c7d
BLAKE2b-256 checksum
How to use checksums
cbd02e9e0d79fc02587fb08e4193e2ad88fd7b6e308f96fe1da144677440d55b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / vamp_graphql_audit-1.3.0-py3-none-any.whl

Download URL vamp_graphql_audit-1.3.0-py3-none-any.whl
Size 32.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
274ef3ab6fa925c842f873b4b40ec19b96e94301dd4f28b5c2ecdbfbba3b973a
BLAKE2b-256 checksum
How to use checksums
4dc7ef04997613a662375be0622a4999aa8e74f9a01a39e125c4adf2dc8b1249
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

1.4.0

2 release files

This release

1.3.0 This release

2 release files

1.2.0

2 release files

1.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page