Hoppscotch

Hoppscotch

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 02.04.2026 19:21:35
  • Zuletzt bearbeitet 15.04.2026 17:24:29

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfiltration. With these tokens, the attacker can sign in as the victim to takeover their account. This iss...

  • EPSS 0.03%
  • Veröffentlicht 02.04.2026 19:20:00
  • Zuletzt bearbeitet 15.04.2026 17:24:56

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow tooltip via display name. This issue has been patched in version 2026.3.0.

  • EPSS 0.06%
  • Veröffentlicht 02.04.2026 19:19:15
  • Zuletzt bearbeitet 15.04.2026 17:23:38

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 02.04.2026 19:19:05
  • Zuletzt bearbeitet 15.04.2026 17:27:18

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. The redirect query parameter is directly used to construct a URL and redirect the user without proper...

  • EPSS 0.01%
  • Veröffentlicht 07.03.2026 05:13:13
  • Zuletzt bearbeitet 11.03.2026 19:01:34

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authenticated user to delete any other user's PAT by providing its ID, with no ownership verification. This iss...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 26.02.2026 22:38:33
  • Zuletzt bearbeitet 27.02.2026 15:50:55

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection ID and returns the full collection data — including title, type, and the serialized `data` field con...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 26.02.2026 22:36:50
  • Zuletzt bearbeitet 27.02.2026 15:51:42

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's personal environment by ID. `user-environments.resolver.ts:82-109`, `updateUserEnvironment` mutation uses ...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 26.02.2026 22:34:46
  • Zuletzt bearbeitet 27.02.2026 15:53:07

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instance including OAuth provider credentials and SMTP se...

  • EPSS 0.12%
  • Veröffentlicht 08.05.2024 15:15:11
  • Zuletzt bearbeitet 15.04.2026 00:35:42

@hoppscotch/cli is a CLI to run Hoppscotch Test Scripts in CI environments. Prior to 0.8.0, the @hoppscotch/js-sandbox package provides a Javascript sandbox that uses the Node.js vm module. However, the vm module is not safe for sandboxing untrusted ...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 29.02.2024 01:44:19
  • Zuletzt bearbeitet 01.04.2025 15:22:06

Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with Spoofed Content as Hoppscotch. Part of payload (external link) is presented in clickable form - easie...