hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingCompleted and canReRunOnboarding before allowing config overwrites. However, GET /v1/onboarding/config still leaks all infrastructure secrets in plaintext to unauthenticated users when the ONBOARDING_RECOVERY_TOKEN stored in the database is an empty string. This vulnerability is fixed in 2026.4.0.
Metrics
Affected Vendors & Products
References
History
Thu, 14 May 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hoppscotch
Hoppscotch hoppscotch |
|
| Vendors & Products |
Hoppscotch
Hoppscotch hoppscotch |
Wed, 13 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingCompleted and canReRunOnboarding before allowing config overwrites. However, GET /v1/onboarding/config still leaks all infrastructure secrets in plaintext to unauthenticated users when the ONBOARDING_RECOVERY_TOKEN stored in the database is an empty string. This vulnerability is fixed in 2026.4.0. | |
| Title | hoppscotch: Unauthenticated Onboarding Config Disclosure via Empty Recovery Token | |
| Weaknesses | CWE-284 CWE-287 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-05-13T21:47:01.158Z
Updated: 2026-05-13T21:47:01.158Z
Reserved: 2026-05-06T17:18:51.782Z
Link: CVE-2026-44478
No data.
Status : Received
Published: 2026-05-13T22:16:46.207
Modified: 2026-05-13T22:16:46.207
Link: CVE-2026-44478
No data.
ReportizFlow