Web Hack List

Collected research

That single GraphQL issue that you keep missing

GraphQL endpoints can remain CSRF-prone when middleware accepts form-encoded POST bodies, mutations are allowed over GET, or state-changing operations are exposed as queries. The article shows how these behaviors enable browser-driven mutations and XS-Search timing probes, then outlines framework, origin, cookie, and method-based defenses.

Record

Researcher
Tomasz Swiadek and Andrea Brancaleoni

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Tomasz Swiadek and Andrea Brancaleoni, first published at the original source. Preserved copies are kept so the citation survives its host.