CVE-2026-30825

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authenticated user to delete any other user's PAT by providing its ID, with no ownership verification. This issue has been patched in version 2026.2.1.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:hoppscotch:hoppscotch:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-07 06:16

Updated : 2026-03-11 19:01


NVD link : CVE-2026-30825

Mitre link : CVE-2026-30825

CVE.ORG link : CVE-2026-30825


JSON object : View

Products Affected

hoppscotch

  • hoppscotch
CWE
CWE-639

Authorization Bypass Through User-Controlled Key