CVE-2026-34931
High
High exploit probability or critical severity with a known exploit.
CVSS base
9.6
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.4%
31.2th percentile
CISA KEV
Not listed
Weakness / dates
CWE-601
Published 2026-04-02 · modified 2026-07-24
Description
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfiltration. With these tokens, the attacker can sign in as the victim to takeover their account. This issue has been patched in version 2026.3.0.