GitPedia

Vulnapi

API Security Vulnerability Scanner designed to help you secure your APIs.

From cerberauth·Updated June 28, 2026·View on GitHub·

VulnAPI is an Open-Source DAST designed to help you scan your APIs for common security vulnerabilities and weaknesses. The project is written primarily in Go, distributed under the MIT License license, first published in 2023. Key topics include: api-security, api-security-testing, api-testing, authentication, authorization.

Latest release: v0.9.0
April 14, 2026View Changelog →
<p align="center"> <img src="https://vulnapi.cerberauth.com/logo-ascii-text-art.png" height="150" alt="vulnapi logo"> </p>

Join Discord
GitHub Workflow Status
Latest version
Github Repo Stars
License

VulnAPI: An API Security Vulnerability Scanner

VulnAPI is an Open-Source DAST designed to help you scan your APIs for common security vulnerabilities and weaknesses.

By using this tool, you can detect and mitigate security vulnerabilities in your APIs before they are exploited by attackers.

Demo

Installation

Before making your first scan with VulnAPI, you have to download and install it. Please follow the instructions on the Installation documentation page.

Documentation

Before scanning, you can discover target API useful information by using the discover command.

The Vulnerability Scanner CLI offers two methods for scanning APIs:

  • Using Curl-like CLI: This method involves directly invoking the CLI with parameters resembling curl commands.
  • Using OpenAPI Contracts: This method utilizes OpenAPI contracts to specify API endpoints for scanning.

Discover Command

To discover target API useful information, leaked files and well-known path execute the following command:

bash
vulnapi discover api [API_URL]

Example output:

bash
| TYPE | URL | |---------------|---------------------------------------------| | OpenAPI | http://localhost:5000/openapi.json | | GraphQL | http://localhost:5000/graphql | | Well-Known | http://localhost:8080/.well-known/jwks.json | | Exposed Files | http://localhost:8080/.env.dev | | TECHNOLOGIE/SERVICE | VALUE | |---------------------|---------------| | Framework | Flask:2.2.3 | | Language | Python:3.7.17 | | Server | Flask:2.2.3 |

Using Curl-like CLI

To perform a scan using the Curl-like CLI, execute the following command:

bash
vulnapi scan curl [API_URL] [CURL_OPTIONS]

Replace [API_URL] with the URL of the API to scan, and [CURL_OPTIONS] with any additional curl options you wish to include.

Using OpenAPI Contracts

To perform a scan using OpenAPI contracts, execute the following command:

bash
echo "[JWT_TOKEN]" | vulnapi scan openapi [PATH_OR_URL_TO_OPENAPI_FILE]

Replace [PATH_OR_URL_TO_OPENAPI_FILE] with the path or the URL to the OpenAPI contract JSON file and [JWT_TOKEN] with the JWT token to use for authentication.

Output

The CLI provides detailed reports on any vulnerabilities detected during the scan. Below is an example of the output format:

TECHNOLOGIE/SERVICEVALUE
FrameworkFlask:2.2.3
LanguagePython:3.11.9
ServerFlask:2.2.3

Advice: There are some low-risk issues. It's advised to take a look.

OPERATIONRISK LEVELCVSS 4.0 SCOREOWASPVULNERABILITY
GET /Medium5.1API8:2023 SecurityX-Frame-Options Header is
Misconfigurationmissing
Medium5.1API8:2023 SecurityCORS Headers are missing
Misconfiguration
Medium5.1API8:2023 SecurityCSP frame-ancestors policy is
Misconfigurationnot set
Info0.0API8:2023 SecurityX-Content-Type-Options Header
Misconfigurationis missing
Info0.0API8:2023 SecurityOperation May Accepts
MisconfigurationUnauthenticated Requests
Info0.0API8:2023 SecurityHSTS Header is missing
Misconfiguration
Info0.0API8:2023 SecurityCSP Header is not set
Misconfiguration
GET /books/v1Medium5.1API8:2023 SecurityCSP frame-ancestors policy is
Misconfigurationnot set
Medium5.1API8:2023 SecurityX-Frame-Options Header is
Misconfigurationmissing
Medium5.1API8:2023 SecurityCORS Headers are missing
Misconfiguration
Info0.0API8:2023 SecurityCSP Header is not set
Misconfiguration
Info0.0API8:2023 SecurityHSTS Header is missing
Misconfiguration
Info0.0API8:2023 SecurityX-Content-Type-Options Header
Misconfigurationis missing
Info0.0API8:2023 SecurityOperation May Accepts
MisconfigurationUnauthenticated Requests

In this example, each line represents a detected vulnerability, severity level (critical), vulnerability type, affected operation (GET http://localhost:8080/), and a description of the vulnerability.

Vulnerabilities Detected

All the vulnerabilities detected by the project are listed at this URL: API Vulnerabilities Detected.

More vulnerabilities and best practices will be added in future releases. If you have any suggestions or requests for additional vulnerabilities or best practices to be included, please feel free to open an issue or submit a pull request.

Proxy Support

The scanner supports proxy configurations for scanning APIs behind a proxy server. To use a proxy, set the HTTP_PROXY or HTTPS_PROXY environment variables with the proxy URL.

A command arg --proxy is also available to specify the proxy URL.

Additional Options

The VulnAPI may support additional options for customizing scans or output formatting. Run vulnapi -h or vulnapi help command to view available options and their descriptions.

Telemetry

The scanner collects anonymous usage data to help improve the tool. This data includes the number of scans performed, number of detected vulnerabilities, and the severity of vulnerabilities. No sensitive information is collected. You can opt-out of telemetry by passing the --sqa-opt-out flag.

Complete CLI Help

To view the complete CLI help, execute the following command:

bash
vulnapi -h

Here is the output of the help command:

bash
vulnapi Usage: vulnapi [command] Available Commands: completion Generate the autocompletion script for the specified shell help Help about any command jwt Generate JWT tokens scan API Scan serve Start the server Flags: -h, --help help for vulnapi --sqa-opt-out Opt out of sending anonymous usage statistics and crash reports to help improve the tool Use "vulnapi [command] --help" for more information about a command.

Disclaimer

This scanner is provided for educational and informational purposes only. It should not be used for malicious purposes or to attack any system without proper authorization. Always respect the security and privacy of others.

Thanks

This project used the following open-source libraries:

License

This repository is licensed under the MIT License @ CerberAuth. You are free to use, modify, and distribute the contents of this repository for educational and testing purposes.

Contributors

Showing top 3 contributors by commit count.

View all contributors on GitHub →

This article is auto-generated from cerberauth/vulnapi via the GitHub API.Last fetched: 6/29/2026