DOM-based Open Redirect in Hoppscotch API Development Ecosystem
CVE-2026-34847
4.7MEDIUM
What is CVE-2026-34847?
The Hoppscotch API Development Ecosystem is vulnerable to a DOM-based open redirect flaw, present in versions prior to 2026.3.0. This vulnerability arises from the improper handling of the redirect query parameter on the /enter page, allowing an attacker to manipulate the URL to redirect users to malicious sites without sufficient validation. This issue has been addressed in version 2026.3.0, which provides necessary patches to enhance security.
Affected Version(s)
hoppscotch < 2026.3.0
