#TheFutureIsBright #BugBounty #bugbountytips Broken Crystals by https://brightsec.com
Lab: https://brokencrystals.com
https://brokencrystals.com/graphql is a vulnerable entry point where introspection is enabled. Attacker can chain this misconfiguration with OS command injection
GraphQL voyager: https://graphql-kit.com/graphql-voyager