GraphQL introspection is enabled
Evidence
GET https://api.example.com/graphql?query={__schema{types{name}}} → 200 OK
content-type: application/json
{"data":{"__schema":{"types":[{"name":"Query"},{"name":"User"},{"name":"Invoice"}, …How to fix it
Decide whether your GraphQL API is meant to be public. If it is not, disable introspection in production. In most servers this is one setting — for example, introspection: false in the server options, enabled only in development. If clients need the schema, publish it to them through your documentation or build tooling instead. Re-test the finding from your report.