CVE-2026-59720

HIGH

Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server

Title source: cna
STIX 2.1

Description

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPublic to true, causing mock servers linked to private collections to be publicly accessible without authentication and potentially expose sensitive API data. This issue is fixed in version 2026.6.0.

Scores

CVSS v3 7.5
EPSS 0.0034
EPSS Percentile 26.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-200 CWE-284
Status published
Products (1)
hoppscotch/hoppscotch < 2026.6.0
Published Jul 09, 2026
Tracked Since Jul 09, 2026