Intel

AIKIDO-2026-10461

hoppscotch-backend is vulnerable to Open Redirect

Open RedirectCVE-2026-34931

55

Medium Risk

This Affects:

JShoppscotch-backend
0.0.1 - 2026.2.1
Fixed in 2026.3.0

TL;DR

Affected versions of this package are vulnerable to an open redirect that leads to token exfiltration. With these tokens, the attacker can sign in as the victim to takeover their account.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

hoppscotch-backend is vulnerable to Open Redirect in versions 0.0.1 - 2026.2.1.

How to fix this

Upgrade the hoppscotch-backend library to the patch version.