CVE-2026-59721

HIGH

Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection

Title source: cna
STIX 2.1

Description

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in utils.ts permits path, query, or fragment content that nodemailer parses into sendmail transport options, allowing an admin to execute arbitrary commands as root in the backend container after restart and mail sending. This issue is fixed in version 2026.6.0.

Scores

CVSS v3 7.2
EPSS 0.0052
EPSS Percentile 41.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77 CWE-78 CWE-915
Status published
Products (1)
hoppscotch/hoppscotch < 2026.6.0
Published Jul 09, 2026
Tracked Since Jul 09, 2026