hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authenticated user to delete any other user's PAT by providing its ID, with no ownership verification. This issue has been patched in version 2026.2.1.
History

Mon, 09 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Hoppscotch
Hoppscotch hoppscotch
Vendors & Products Hoppscotch
Hoppscotch hoppscotch

Sat, 07 Mar 2026 05:30:00 +0000

Type Values Removed Values Added
Description hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authenticated user to delete any other user's PAT by providing its ID, with no ownership verification. This issue has been patched in version 2026.2.1.
Title hoppscotch: IDOR - Any authenticated user can revoke any other user's Personal Access Token
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-03-07T05:13:13.987Z

Updated: 2026-03-09T20:42:45.007Z

Reserved: 2026-03-05T21:06:44.605Z

Link: CVE-2026-30825

cve-icon Vulnrichment

Updated: 2026-03-09T20:42:36.208Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-03-07T06:16:10.343

Modified: 2026-03-09T21:16:19.620

Link: CVE-2026-30825

cve-icon Redhat

No data.