Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

hoppscotch — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting hoppscotch. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Hoppscotch serves as an API development and testing tool, allowing developers to construct and send HTTP requests. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for its 13 recorded CVEs. Notable security characteristics include its client-side nature, which limits some attack surfaces, though vulnerabilities have often stemmed from improper input validation and insecure default configurations. While no major public security incidents have been widely documented, the consistent discovery of RCE and XSS vulnerabilities in its versions highlights ongoing security challenges that require careful implementation and regular updates.

CVE ID Title CVSS Severity Published
CVE-2026-69189 Hoppscotch: Cross-user private data exposure and UserHistory IDOR via team GraphQL resolvers — hoppscotch CWE-200 7.6 High 2026-08-18
CVE-2026-59720 Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server — hoppscotch CWE-200 7.5 High 2026-07-09
CVE-2026-59721 Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection — hoppscotch CWE-77 7.2 High 2026-07-09
CVE-2026-50160 Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite — hoppscotch CWE-915 10.0 Critical 2026-07-01
CVE-2026-44478 hoppscotch: Unauthenticated Onboarding Config Disclosure via Empty Recovery Token — hoppscotch CWE-284 7.5 High 2026-05-13
CVE-2026-34931 hoppscotch: Improper loopback redirect_uri validation in device-login flow — hoppscotch CWE-601 6.1AI Medium AI 2026-04-02
CVE-2026-34848 hoppscotch: Stored XSS in team member overflow tooltip via display name — hoppscotch CWE-79 5.4 Medium 2026-04-02
CVE-2026-34932 hoppscotch: Stored XSS via mock server responses on backend origin — hoppscotch CWE-79 8.1AI High AI 2026-04-02
CVE-2026-34847 hoppscotch: Open redirect via `/enter?redirect=` — hoppscotch CWE-601 4.7 Medium 2026-04-02
CVE-2026-30825 hoppscotch: IDOR - Any authenticated user can revoke any other user's Personal Access Token — hoppscotch CWE-639 - - 2026-03-07
CVE-2026-28217 IDOR in GraphQL userCollection Query Exposes Other Users' Private Collections — hoppscotch CWE-862 6.5 Medium 2026-02-26
CVE-2026-28216 hoppscotch has IDOR in updateUserEnvironment / deleteUserEnvironment — hoppscotch CWE-639 8.3 High 2026-02-26
CVE-2026-28215 hoppscotch Vulnerable to Unauthenticated Onboarding Config Takeover — hoppscotch CWE-284 9.1 Critical 2026-02-26
CVE-2024-34714 Hoppscotch Extension responds to calls made by origins not in the domain list — hoppscotch-extension CWE-354 7.6 High 2024-05-14
CVE-2024-34347 @hoppscotch/cli affected by Sandbox Escape in @hoppscotch/js-sandbox leads to RCE — hoppscotch CWE-77 8.4 High 2024-05-08
CVE-2024-27092 Content spoofing - real Hoppscotch emails — hoppscotch CWE-20 5.4 Medium 2024-02-26
CVE-2023-34097 Database password exposed in logs in hoppscotch — hoppscotch CWE-532 7.8 High 2023-06-05
CVE-2022-0121 Cross-site Scripting in hoppscotch/hoppscotch — hoppscotch/hoppscotch CWE-79 8.0 High 2022-01-06

This page lists every published CVE security advisory associated with hoppscotch. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.