Executive brief
A critical vulnerability exists in Hoppscotch, a popular tool for API development, specifically affecting self-hosted deployments. An attacker can exploit a flaw in the initial setup process to overwrite the system's security keys without needing a password. This allows the attacker to forge administrative credentials, leading to a total takeover of the server and access to all user data.
Technical details
A mass assignment vulnerability exists in the 'POST /v1/onboarding/config' endpoint of hoppscotch-backend. The root cause is a combination of four weaknesses: the NestJS ValidationPipe is configured without 'whitelist: true', allowing extra request body properties to persist; the service layer iterates through these properties using 'Object.entries' without runtime validation; the 'validateEnvValues' function lacks explicit checks for sensitive keys (falling through to a default break); and the endpoint lacks authentication. An unauthenticated remote attacker can exploit this on fresh installations (where no users exist) to overwrite 'JWT_SECRET' and 'SESSION_SECRET'. By controlling the JWT signing key, the attacker can forge tokens for any user, including administrators, achieving full remote code execution or server compromise. The issue is resolved in version 2026.5.0 by enabling strict validation whitelisting and service-level allowlists.
Affected products
- Hoppscotch hoppscotch-backend (Self-Hosted) <= 2026.4.1
Timeline
- 2026-04-21: patched: Initial pull request for fix submitted
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-06-23: disclosed: Public disclosure on oss-security mailing list
- 2026-07-01: advisory: NVD publication date