JSON injection exploits improper handling of JSON input to manipulate application logic, bypass authentication, or extract sensitive data from backend systems.
JSON injection occurs when untrusted data is inserted into a JSON structure without proper sanitization. Attackers craft malicious JSON payloads to alter application logic, bypass authentication, or exfiltrate data. It targets APIs and web applications that parse JSON input from users without strict validation or encoding of special characters.
While SQL injection targets database query languages, JSON injection manipulates the structure of JSON documents. Both exploit insufficient input validation, but JSON injection focuses on altering key-value pairs, injecting additional fields, or breaking JSON parsers. The attack surface is typically REST APIs and modern web services rather than traditional database-driven forms.
Common vectors include manipulating API request bodies, injecting extra JSON keys to override server-side defaults, exploiting lenient parsers that accept duplicate keys, and embedding malicious payloads in nested objects. Attackers may also target JSON Web Tokens or configuration files that accept user-controlled JSON data without schema validation.
Developers should use strict JSON schema validation, employ parameterized serialization libraries, reject duplicate keys, and sanitize all user input before incorporating it into JSON structures. Server-side allowlisting of expected fields, using strongly typed deserialization, and applying Content-Type enforcement are essential defensive measures.
Burp Suite with custom intruder payloads, OWASP ZAP, and specialized API fuzzing tools like RESTler and Schemathesis can detect JSON injection flaws. Manual testing with crafted payloads remains critical. Static analysis tools that understand JSON parsing patterns also help identify vulnerable code paths during development.
In certain scenarios, JSON injection can escalate to remote code execution. If injected JSON reaches server-side template engines, deserialization routines, or eval-like functions, attackers can execute arbitrary code. This is especially dangerous in Node.js applications using unsafe deserialization or dynamic property assignment from parsed JSON.
JSON hijacking is a related attack where an attacker intercepts JSON responses intended for authenticated users by overriding JavaScript array or object constructors. While modern browsers have mitigated classic JSON hijacking, variants still exist. Both attacks exploit how applications handle JSON data but target different phases of the request-response cycle.
JSON injection poses significant risks to API security by enabling parameter pollution, privilege escalation through field injection, and business logic bypass. Attackers can add administrative flags, modify pricing data, or alter workflow states. API gateways with strict schema enforcement and request validation policies are critical countermeasures.