DOM-based Open Redirect in Hoppscotch API Development Ecosystem
CVE-2026-34847

4.7MEDIUM

Key Information:

Vendor

Hoppscotch

Vendor
CVE Published:
2 April 2026

What is CVE-2026-34847?

The Hoppscotch API Development Ecosystem is vulnerable to a DOM-based open redirect flaw, present in versions prior to 2026.3.0. This vulnerability arises from the improper handling of the redirect query parameter on the /enter page, allowing an attacker to manipulate the URL to redirect users to malicious sites without sufficient validation. This issue has been addressed in version 2026.3.0, which provides necessary patches to enhance security.

Affected Version(s)

hoppscotch < 2026.3.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.