Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPublic to true, causing mock servers linked to private collections to be publicly accessible without authentication and potentially expose sensitive API data. This issue is fixed in version 2026.6.0.
References
Configurations
No configuration.
History
09 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-c68f-wr5p-j6jf - |
09 Jul 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-09 18:16
Updated : 2026-07-10 19:15
NVD link : CVE-2026-59720
Mitre link : CVE-2026-59720
CVE.ORG link : CVE-2026-59720
JSON object : View
Products Affected
No product.
