CVE-2026-59720
HIGHHoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server
Title source: cnaDescription
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPublic to true, causing mock servers linked to private collections to be publicly accessible without authentication and potentially expose sensitive API data. This issue is fixed in version 2026.6.0.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-c68f-wr5p-j6jf
X_Refsource_Misc x_refsource_misc
https://github.com/hoppscotch/hoppscotch/pull/6410
X_Refsource_Misc x_refsource_misc
https://github.com/hoppscotch/hoppscotch/commit/e4332110d455a3012d5c77a9186bc4aa096e34f2
X_Refsource_Misc x_refsource_misc
https://github.com/hoppscotch/hoppscotch/releases/tag/2026.6.0
Scores
CVSS v3
7.5
EPSS
0.0034
EPSS Percentile
26.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
CWE-284
Status
published
Products (1)
hoppscotch/hoppscotch
< 2026.6.0
Published
Jul 09, 2026
Tracked Since
Jul 09, 2026