Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

hoppscotch — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in hoppscotch, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with Hoppscotch, an open-source API development platform. The collection encompasses a diverse range of flaws reported over the past five years, including cross-site scripting, prototype pollution, and improper input validation issues. Readers can utilize this resource to track the vendor's security advisories, understand specific weakness classes affecting API clients, and review the product's historical vulnerability landscape. By consolidating data from multiple sources, this index provides a centralized view of security incidents without requiring navigation across disparate databases. The entries are organized chronologically and by severity, allowing developers and security professionals to identify patterns in reported bugs. This aggregation supports risk assessment for organizations relying on Hoppscotch within their development workflows. It highlights recurring themes in the software's security posture, such as client-side injection risks and dependency vulnerabilities. The data reflects publicly disclosed issues that have been verified by the community or the development team. Users can filter results to focus on specific vulnerability types or time periods, facilitating targeted analysis of the product's security evolution. This page serves as a factual reference for understanding the security history of this particular tool, enabling informed decisions regarding its use in production environments.

Vendor: hoppscotch

CVE ID Title CVSS Severity Published
CVE-2026-69189 Hoppscotch: Cross-user private data exposure and UserHistory IDOR via team GraphQL resolvers CWE-200 7.6 High 2026-08-18
CVE-2026-59720 Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server CWE-200 7.5 High 2026-07-09
CVE-2026-59721 Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection CWE-77 7.2 High 2026-07-09
CVE-2026-50160 Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite CWE-915 10.0 Critical 2026-07-01
CVE-2026-44478 hoppscotch: Unauthenticated Onboarding Config Disclosure via Empty Recovery Token CWE-284 7.5 High 2026-05-13
CVE-2026-34931 hoppscotch: Improper loopback redirect_uri validation in device-login flow CWE-601 6.1AI Medium AI 2026-04-02
CVE-2026-34848 hoppscotch: Stored XSS in team member overflow tooltip via display name CWE-79 5.4 Medium 2026-04-02
CVE-2026-34932 hoppscotch: Stored XSS via mock server responses on backend origin CWE-79 8.1AI High AI 2026-04-02
CVE-2026-34847 hoppscotch: Open redirect via `/enter?redirect=` CWE-601 4.7 Medium 2026-04-02
CVE-2026-30825 hoppscotch: IDOR - Any authenticated user can revoke any other user's Personal Access Token CWE-639 - - 2026-03-07
CVE-2026-28217 IDOR in GraphQL userCollection Query Exposes Other Users' Private Collections CWE-862 6.5 Medium 2026-02-26
CVE-2026-28216 hoppscotch has IDOR in updateUserEnvironment / deleteUserEnvironment CWE-639 8.3 High 2026-02-26
CVE-2026-28215 hoppscotch Vulnerable to Unauthenticated Onboarding Config Takeover CWE-284 9.1 Critical 2026-02-26
CVE-2024-34347 @hoppscotch/cli affected by Sandbox Escape in @hoppscotch/js-sandbox leads to RCE CWE-77 8.4 High 2024-05-08
CVE-2024-27092 Content spoofing - real Hoppscotch emails CWE-20 5.4 Medium 2024-02-26
CVE-2023-34097 Database password exposed in logs in hoppscotch CWE-532 7.8 High 2023-06-05

All 16 known CVE vulnerabilities affecting hoppscotch with full Chinese analysis, references, and POCs where available.