Executive brief
Hoppscotch is an open-source platform used by developers to build and test APIs. A security flaw in the login page allows attackers to create malicious links that look legitimate but automatically redirect users to external, untrusted websites. This could be used in phishing campaigns to trick users into visiting fake login pages or downloading malware.
Technical details
A DOM-based open redirect vulnerability exists in the Hoppscotch web frontend within the `/enter` page component (`enter.vue`). The application extracts the `redirect` query parameter and uses it to construct a new URL object without validating the destination domain. Specifically, the `mounted()` lifecycle hook takes the user-controlled input, appends additional query parameters, and assigns the result directly to `window.location.href`. An attacker can exploit this by crafting a URL that redirects a victim to a malicious site. This issue is patched in version 2026.3.0 by implementing proper validation of the redirect target.
Affected products
- Hoppscotch Hoppscotch < 2026.3.0
Timeline
- 2026-03-31: patched: Version 2026.3.0 released
- 2026-03-31: advisory: GitHub Security Advisory GHSA-27pm-c9ch-746q published
- 2026-04-02: disclosed: CVE-2026-34847 published to NVD