Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

hoppscotch — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in hoppscotch, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security weaknesses within Hoppscotch, an open-source API development platform, categorized by vulnerability types and associated tags. It aggregates data on diverse security issues including cross-site scripting, improper access control, and information disclosure affecting the software and its dependencies. The collection covers reported vulnerabilities from the initial release of the product through recent updates, providing a comprehensive historical record of security incidents. Visitors can use this resource to track vendor advisories related to Hoppscotch, gaining insight into how the development team addresses reported issues over time. Users can also explore specific weakness classes to understand the nature and severity of bugs that have impacted the platform. Furthermore, the page allows for the lookup of a product's vulnerability history, enabling security professionals and developers to assess the overall security posture and evolution of the codebase. By centralizing this information, the page serves as a reference for auditing the software and understanding the context of past security patches. This systematic approach helps in evaluating the reliability of the tool for API testing and development workflows. The data is presented to facilitate informed decision-making regarding the adoption and configuration of Hoppscotch in various development environments.

Vendor: hoppscotch

CVE IDTitleCVSSSeverityPublished
CVE-2026-69189 Hoppscotch: Cross-user private data exposure and UserHistory IDOR via team GraphQL resolvers CWE-200 7.6 High2026-08-18
CVE-2026-59720 Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server CWE-200 7.5 High2026-07-09
CVE-2026-59721 Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection CWE-77 7.2 High2026-07-09
CVE-2026-50160 Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite CWE-915 10.0 Critical2026-07-01
CVE-2026-44478 hoppscotch: Unauthenticated Onboarding Config Disclosure via Empty Recovery Token CWE-284 7.5 High2026-05-13
CVE-2026-34931 hoppscotch: Improper loopback redirect_uri validation in device-login flow CWE-601 6.1AIMediumAI2026-04-02
CVE-2026-34848 hoppscotch: Stored XSS in team member overflow tooltip via display name CWE-79 5.4 Medium2026-04-02
CVE-2026-34932 hoppscotch: Stored XSS via mock server responses on backend origin CWE-79 8.1AIHighAI2026-04-02
CVE-2026-34847 hoppscotch: Open redirect via `/enter?redirect=` CWE-601 4.7 Medium2026-04-02
CVE-2026-30825 hoppscotch: IDOR - Any authenticated user can revoke any other user's Personal Access Token CWE-639--2026-03-07
CVE-2026-28217 IDOR in GraphQL userCollection Query Exposes Other Users' Private Collections CWE-862 6.5 Medium2026-02-26
CVE-2026-28216 hoppscotch has IDOR in updateUserEnvironment / deleteUserEnvironment CWE-639 8.3 High2026-02-26
CVE-2026-28215 hoppscotch Vulnerable to Unauthenticated Onboarding Config Takeover CWE-284 9.1 Critical2026-02-26
CVE-2024-34347 @hoppscotch/cli affected by Sandbox Escape in @hoppscotch/js-sandbox leads to RCE CWE-77 8.4 High2024-05-08
CVE-2024-27092 Content spoofing - real Hoppscotch emails CWE-20 5.4 Medium2024-02-26
CVE-2023-34097 Database password exposed in logs in hoppscotch CWE-532 7.8 High2023-06-05

All 16 known CVE vulnerabilities affecting hoppscotch with full Chinese analysis, references, and POCs where available.