GraphQL RCE: The Kill Chain to Cloud Identity…!
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A bug bounty writeup detailing a full kill chain from a GraphQL endpoint to Google Cloud identity compromise. Starting with GraphQL introspection to enumerate workspace and app IDs, the attacker exploited a custom Python function feature by injecting payloads via the `createUserDefinedFunction` mutation. The sandbox escape was
Sort: