These vulnerabilities are often found by your own developers, security researchers doing responsible disclosure, or — if you're unlucky — by someone browsing your app out of curiosity. The attacker doesn't need to "hack" anything. They just need to read or send a JSON field.