Aikido Attack finds multiple 0-days in Hoppscotch
ID: b6b20780-5b7e-5c61-b968-5bbdb45f0e33
STIX ID: report--b6b20780-5b7e-5c61-b968-5bbdb45f0e33
Feed Name: Aikido Security's Blog
Threat Score
Hoppscotch self-hosted instances (<=2026.2.1) contained three security flaws — an open-redirect enabling session token exfiltration and account takeover, a stored XSS in the Mock Server allowing script execution and data exfiltration, and an access-control flaw that permits injecting requests into other teams' collections — all responsibly disclosed and patched in 2026.3.0.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
