Hoppscotch

Hoppscotch

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 18.08.2026 15:17:00
  • Zuletzt bearbeitet 18.08.2026 16:18:16

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspa...

  • EPSS 0.34%
  • Veröffentlicht 09.07.2026 17:27:34
  • Zuletzt bearbeitet 10.07.2026 19:15:15

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPublic to true, causing mock servers linked to private ...

  • EPSS 0.52%
  • Veröffentlicht 09.07.2026 17:24:46
  • Zuletzt bearbeitet 10.07.2026 19:15:15

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in utils.ts permits path, query, o...

Exploit
  • EPSS 17.75%
  • Veröffentlicht 01.07.2026 17:48:49
  • Zuletzt bearbeitet 02.07.2026 19:45:47

Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpoint is vulnerable to mass assignment. The global NestJS ValidationPipe...

  • EPSS 0.24%
  • Veröffentlicht 13.05.2026 22:16:46
  • Zuletzt bearbeitet 15.05.2026 19:17:00

hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingCompleted and canReRunOnboarding before allowing config ove...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 02.04.2026 19:21:35
  • Zuletzt bearbeitet 24.07.2026 21:10:00

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfiltration. With these tokens, the attacker can sign in as the victim to takeover their account. This iss...

  • EPSS 0.14%
  • Veröffentlicht 02.04.2026 19:20:00
  • Zuletzt bearbeitet 24.07.2026 21:10:00

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow tooltip via display name. This issue has been patched in version 2026.3.0.

  • EPSS 0.29%
  • Veröffentlicht 02.04.2026 19:19:15
  • Zuletzt bearbeitet 24.07.2026 21:10:00

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0.

Exploit
  • EPSS 0.4%
  • Veröffentlicht 02.04.2026 19:19:05
  • Zuletzt bearbeitet 24.07.2026 21:10:00

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. The redirect query parameter is directly used to construct a URL and redirect the user without proper...

  • EPSS 0.23%
  • Veröffentlicht 07.03.2026 05:13:13
  • Zuletzt bearbeitet 11.03.2026 19:01:34

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authenticated user to delete any other user's PAT by providing its ID, with no ownership verification. This iss...