CVE-2026-30825: Hoppscotch
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authenticated user to delete any other user's PAT by providing its ID, with no ownership verification. This issue has been patched in version 2026.2.1.
Affected products
- Hoppscotch Hoppscotch: before 2026.2.1 (fixed in 2026.2.1)
Published 2026-03-07. Last modified 2026-06-17.