DVGA

DVGA

A vulnerable GraphQL application designed for security learning and testing

1,684GitHub
Description

DVGA (Damn Vulnerable GraphQL Application) is a vulnerable GraphQL application designed for security learning and testing. Through DVGA, users can learn and practice how to discover and exploit vulnerabilities in the GraphQL interface in a safe environment, while also learning how to defend against these attacks. Main features: - ** Learning and Practice **: DVGA provides a real vulnerability environment to help users understand common security issues and attack methods in GraphQL. - ** Multiple difficulty modes **: Support both "beginner" and "expert" difficulty modes. There is no security protection in the beginner mode and is suitable for entry learning; in the expert mode, security mechanisms such as query depth limits and request cost analysis are added, which is suitable for advanced challenges. - ** Various interaction methods **: You can operate through a web interface, or interact through APIs or command-line tools. - ** Rich Resources **: A large number of built-in learning resources about GraphQL and its security, including videos and articles, are available to help users systematically improve their skills. Applicable population: - penetration testers - security researcher - developers - Learners interested in GraphQL security Other instructions: DVGA is an open source project, and you are welcome to submit bugs or suggestions on GitHub. If you encounter difficulties during the challenge, you can also check the Solutions page for answers and tips.

Screenshots
Screenshot 1
Mobile Screenshots
Mobile Screenshot 1
App Information
Version
0.1.1
Updated
October 11, 2025
Source Code
dolevf
Platform Support
PCMobile
Keywords
safe shooting range