PT-2026-40829 · Unknown · Hoppscotch
CVE-2026-44478
·
Published
2026-05-13
·
Updated
2026-05-14
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
hoppscotch versions prior to 2026.4.0
Description
An information disclosure issue exists where the 'GET /v1/onboarding/config' endpoint leaks infrastructure secrets in plaintext to unauthenticated users. This occurs specifically when the
ONBOARDING RECOVERY TOKEN stored in the database is an empty string.Recommendations
Update to version 2026.4.0.
Exploit
Fix
Improper Access Control
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hoppscotch