PT-2026-40829 · Unknown · Hoppscotch

CVE-2026-44478

·

Published

2026-05-13

·

Updated

2026-05-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions hoppscotch versions prior to 2026.4.0
Description An information disclosure issue exists where the 'GET /v1/onboarding/config' endpoint leaks infrastructure secrets in plaintext to unauthenticated users. This occurs specifically when the ONBOARDING RECOVERY TOKEN stored in the database is an empty string.
Recommendations Update to version 2026.4.0.

Exploit

Fix

Improper Access Control

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44478
GHSA-7C8P-HJ4P-3Q3F

Affected Products

Hoppscotch