CVE-2026-59721
HIGHHoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection
Title source: cnaDescription
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in utils.ts permits path, query, or fragment content that nodemailer parses into sendmail transport options, allowing an admin to execute arbitrary commands as root in the backend container after restart and mail sending. This issue is fixed in version 2026.6.0.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-v7q6-r45w-2c6r
X_Refsource_Misc x_refsource_misc
https://github.com/hoppscotch/hoppscotch/pull/6413
X_Refsource_Misc x_refsource_misc
https://github.com/hoppscotch/hoppscotch/commit/73a88c82b1b2cada26cc4b2bc095b54554242239
X_Refsource_Misc x_refsource_misc
https://github.com/hoppscotch/hoppscotch/releases/tag/2026.6.0
Scores
CVSS v3
7.2
EPSS
0.0052
EPSS Percentile
41.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-77
CWE-78
CWE-915
Status
published
Products (1)
hoppscotch/hoppscotch
< 2026.6.0
Published
Jul 09, 2026
Tracked Since
Jul 09, 2026