PT-2026-56896 · Unknown · Hoppscotch
CVE-2026-59720
·
Published
2026-07-09
·
Updated
2026-07-09
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hoppscotch versions prior to 2026.6.0
Description
Mock server creation in
mock-server.service.ts fails to persist the isPublic input field. Because schema.prisma defaults isPublic to true, mock servers linked to private collections become publicly accessible without authentication, which may expose sensitive API data.Recommendations
Update to version 2026.6.0.
Exploit
Fix
Information Disclosure
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hoppscotch