PT-2026-22211 · Unknown · Hoppscotch

Tracemint

·

Publicado

2026-02-26

·

Atualizado

2026-03-03

·

CVE-2026-28216

CVSS v3.1

8.3

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions hoppscotch versions prior to 2026.2.0
Description hoppscotch is an API development ecosystem. Prior to version 2026.2.0, any logged-in user could read, modify, or delete another user's personal environment by ID. The issue arises from missing authorization checks in the user-environments.resolver.ts file, specifically within the updateUserEnvironment mutation, which lacks the @GqlUser() decorator. This results in the service receiving only the environment ID and performing a prisma.userEnvironment.update({ where: { id } }) without any ownership filter. The deleteUserEnvironment function also has insufficient checks, only verifying if the target is a global environment. Hoppscotch environments store API keys, auth tokens, and secrets used in API requests. An attacker could obtain another user's environment ID and potentially read, replace, or delete sensitive information. The environment ID format is CUID.
Recommendations Update hoppscotch to version 2026.2.0 or later.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28216
GHSA-72RV-VC3J-5VQR

Produtos afetados

Hoppscotch