Data Exposure in Hoppscotch API Development Ecosystem
CVE-2026-44478

7.5HIGH

Key Information:

Vendor

Hoppscotch

Vendor
CVE Published:
13 May 2026

What is CVE-2026-44478?

Hoppscotch, an open-source API development ecosystem, has a vulnerability that allows unauthenticated users to access sensitive infrastructure secrets in plaintext through the GET /v1/onboarding/config endpoint. This occurs when the ONBOARDING_RECOVERY_TOKEN stored in the database is an empty string. Although the vulnerability was mitigated for the POST request in version 2026.2.0, the exposure remains a critical concern until addressed in version 2026.4.0.

Affected Version(s)

hoppscotch >= 2025.7.0, < 2026.4.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.