Information Disclosure in Hoverfly API Simulation Tool by SpectoLabs
CVE-2025-54376
7.8HIGH
What is CVE-2025-54376?
Hoverfly, an open-source API simulation tool, suffers from an information disclosure vulnerability due to improper access control on its admin WebSocket endpoint. In affected versions (1.11.3 and earlier), this endpoint lacks the requisite authentication middleware that secures the REST admin API. As a result, unauthenticated attackers can exploit this vulnerability to stream sensitive application logs in real-time, revealing internal file paths and request/response bodies. This exposes potentially critical information that could be leveraged for further attacks. Users are encouraged to upgrade to version 1.12.0 or later to mitigate this risk.
Affected Version(s)
hoverfly < 1.12.0