Data Exposure in Hoppscotch API Development Ecosystem
CVE-2026-44478
7.5HIGH
What is CVE-2026-44478?
Hoppscotch, an open-source API development ecosystem, has a vulnerability that allows unauthenticated users to access sensitive infrastructure secrets in plaintext through the GET /v1/onboarding/config endpoint. This occurs when the ONBOARDING_RECOVERY_TOKEN stored in the database is an empty string. Although the vulnerability was mitigated for the POST request in version 2026.2.0, the exposure remains a critical concern until addressed in version 2026.4.0.
Affected Version(s)
hoppscotch >= 2025.7.0, < 2026.4.0
