GraphQL RCE: The Kill Chain to Cloud Identity…!

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A bug bounty writeup detailing a full kill chain from a GraphQL endpoint to Google Cloud identity compromise. Starting with GraphQL introspection to enumerate workspace and app IDs, the attacker exploited a custom Python function feature by injecting payloads via the `createUserDefinedFunction` mutation. The sandbox escape was

5m read timeFrom infosecwriteups.com
Post cover image

Sort: