PT-2026-40829 · Unknown · Hoppscotch
Published
2026-05-13
·
Updated
2026-05-14
·
CVE-2026-44478
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
hoppscotch versions prior to 2026.4.0
Description
An information disclosure issue exists where the 'GET /v1/onboarding/config' endpoint leaks infrastructure secrets in plaintext to unauthenticated users. This occurs specifically when the
ONBOARDING RECOVERY TOKEN stored in the database is an empty string.Recommendations
Update to version 2026.4.0.
Exploit
Fix
Improper Authentication
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hoppscotch