CVE-2026-34847 MEDIUM

CVE-2026-34847: hoppscotch: Open redirect via `/enter?redirect=`

Vendor Hoppscotch
Product hoppscotch
Weakness CWE-601 · Open redirect
Published April 2, 2026
Last update April 3, 2026

CVSS base score

4.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

What the vulnerability does

01Description

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. The redirect query parameter is directly used to construct a URL and redirect the user without proper validation. This issue has been patched in version 2026.3.0.

Key dates

02Disclosure timeline

April 2, 2026 CVE published
April 3, 2026 Record updated