Our take
Overview
Damn Vulnerable RESTaurant is a training API designed to make security flaws available for hands-on investigation. It supports two complementary approaches: developers work through an interactive game to find and fix vulnerabilities, while ethical hackers can explore the API and attempt to escalate privileges.
Use it for API security education and tool testing in a controlled environment, not as a production service. The project uses FastAPI and PostgreSQL, and is intended to be extended with additional vulnerable endpoints.
Key Features
- Intentionally vulnerable API for practical security exercises.
- Interactive developer game focused on identifying and fixing flaws.
- Ethical hacking challenge with a path from a low-privileged API user to root.
- Swagger and Redoc API documentation available when the service is running.
- Docker-based local setup for both game and hacking modes.
- Codespaces option for running the application without a local development environment.
- Python FastAPI and PostgreSQL stack, with a design intended to support extensions.
Use Cases
- Developers can practice finding and remediating API vulnerabilities in an interactive setting.
- Ethical hackers can rehearse manual or automated testing against an intentionally vulnerable target.
- Security engineers can evaluate SAST, DAST, and IaC security tooling in a training environment.
- Instructors and learners can use the challenge alongside API security study materials.
Getting Started
Install Docker and Docker Compose V2, then clone the repository and start either mode:
git clone https://github.com/theowni/Damn-Vulnerable-RESTaurant-API-Game.git
cd Damn-Vulnerable-RESTaurant-API-Game
./start_app.sh
For the interactive developer game, run ./start_game.sh instead. See the README for setup details and Codespaces instructions.
Alternatives
- vuln-bank: Vuln Bank is a broader vulnerable banking app with web, API, GraphQL, and AI scenarios, while Damn-Vulnerable-RESTaurant focuses on REST API training.
| Project | Language | License | Stars | Status |
|---|---|---|---|---|
| Damn-Vulnerable-RESTaurant-API-Game | Python | GPL-3.0 | 939 | Not checked yet |
| vuln-bank | HTML | MIT | 960 | Maintained |
Considerations
- The application is intentionally insecure and should only run in a controlled environment. The project explicitly warns against exposing it to public networks or internet-facing servers.
- Local deployment requires Docker and Docker Compose V2. The API is exposed at
http://localhost:8091by default. - The README describes additional vulnerabilities as planned work, so the exercise content may evolve over time.
- The project is licensed under GPL-3.0.
Found this useful?
Share it with someone who would like Damn-Vulnerable-RESTaurant-API-Game.