FixVibe

// 디스커버리 / 스포트라이트

노출된 API 문서

Public Swagger and OpenAPI docs are an API map for you and for the attacker.

What it is

API documentation is meant to be read. The question is by whom. OpenAPI / Swagger specs are extraordinarily useful in development — they generate clients, drive contract testing, and document the API for new team members — but those same properties make them a recon goldmine when shipped to production. The full structure of every endpoint, every parameter name and type, every authentication scheme, every error response shape, served as a single JSON document at a predictable URL. Frameworks like FastAPI, NestJS, Express with swagger-jsdoc, and Spring Boot Actuator publish these by default; many teams never explicitly turned them off when shipping to prod.

How it happens

Several API frameworks make it one line to publish interactive docs and a machine-readable spec, and FastAPI does it by default. NestJS with its Swagger module, Express with swagger-ui-express, and Spring Boot with springdoc work the same way once added. That is great in development and risky when it stays on in production. The spec lists every route, the HTTP methods it accepts, every parameter with its type, the authentication scheme, and sometimes example payloads and responses. The attacker doesn't have to fuzz; they have the contract.

What an attacker gets

Reduces the attacker's effort dramatically. Instead of fuzzing for endpoints (slow, noisy, partial coverage), they have the complete list with parameter names and types. This makes targeted attacks against authorization gaps (IDOR, mass assignment), input validation flaws (SQL/NoSQL injection), and rate-limit bypasses much more efficient. For B2B SaaS, exposed docs also leak product surface — knowing which admin endpoints exist may inform competitive intelligence as much as attack planning.

// what fixvibe reports

What FixVibe reports

Runs on every URL scan: paste your app's URL, nothing to install. The free preview shows your top findings; Hobby and above unlock the full report. Each finding shows the affected URL or host, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Gate API documentation behind authentication, or remove it from production entirely. The cleanest pattern: serve docs only in development environments via env-driven config. FastAPI: `app = FastAPI(docs_url=None, redoc_url=None, openapi_url=None)` in production. NestJS: only call `SwaggerModule.setup` when `process.env.NODE_ENV !== 'production'`. Spring Boot: exclude springfox/springdoc dependencies from prod builds, or set `springdoc.api-docs.enabled=false`. If documentation is needed for partners or developers, host it on a separate authenticated subdomain that doesn't expose the live API. As a defense-in-depth layer, configure your edge (CDN, WAF) to block requests to the standard documentation paths in production.

// 내 앱에서 직접 실행해보세요

FixVibe가 지켜보는 동안 계속 배포하세요.

Paste your app's URL for a free preview. Nothing to install.

디스커버리
133
이 카테고리에서 실행되는 테스트
모듈
16
전용 디스커버리 검사
every URL scan
230+
passive checks on each scan
Scan your URL free →

// 최신 체크 · 실용적인 수정 · 자신 있게 배포

노출된 API 문서: what it is and how to fix it · FixVibe