{"repo":"cerberauth/vulnapi","free":true,"listed":false,"github":"https://github.com/cerberauth/vulnapi","clone":"git clone https://github.com/cerberauth/vulnapi.git","description":"API Security Vulnerability Scanner designed to help you secure your APIs.","language":"Go","stars":279,"topics":["jwt","vulnerability-scanners","cybersecurity","dast","graphql","openapi","security-scanner","security-tools","api-security","api-testing"],"license":"MIT","category":"api-integrations-sdks","readme_excerpt":"--- VulnAPI: An API Security Vulnerability Scanner VulnAPI is an Open-Source DAST designed to help you scan your APIs for common security vulnerabilities and weaknesses. By using this tool, you can detect and mitigate security vulnerabilities in your APIs before they are exploited by attackers. Installation Before making your first scan with VulnAPI, you have to download and install it. Please follow the instructions on the Installation documentation page. Documentation Before scanning, you can discover target API useful information by using the discover command. The Vulnerability Scanner CLI offers two methods for scanning APIs: Using Curl-like CLI : This method involves directly invoking the CLI with parameters resembling curl commands. Using OpenAPI Contracts : This method utilizes OpenAPI contracts to specify API endpoints for scanning. Discover Command To discover target API useful information, leaked files and well-known path execute the following command: Example output: Using Curl-like CLI To perform a scan using the Curl-like CLI, execute the following command: Replace [API URL] with the URL of the API to scan, and [CURL OPTIONS] with any additional curl options you wish to include. Using OpenAPI Contracts To perform a scan using OpenAPI contracts, execute the following command: Replace [PATH OR URL TO OPENAPI FILE] with the path or the URL to the OpenAPI contract JSON file and [JWT TOKEN] with the JWT token to use for authentication. Output The CLI provides detailed","default_branch":null,"files":null,"tree":[],"storefront":"/r/cerberauth","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/cerberauth/vulnapi/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}