CVE-2026-34932: hoppscotch: Stored XSS via mock server responses on backend origin
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
hoppscotchto a version that resolves this vulnerability.Fixed in 2026.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34932?
CVE-2026-34932 has a severity rating that indicates it can lead to stored cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2026-34932?
To fix CVE-2026-34932, you should upgrade to Hoppscotch version 2026.3.0 or later.
What is stored XSS in CVE-2026-34932?
Stored XSS in CVE-2026-34932 refers to a vulnerability where malicious scripts are stored on the server and executed in the context of a user's browser.
Which versions of Hoppscotch are affected by CVE-2026-34932?
Versions of Hoppscotch prior to 2026.3.0 are affected by CVE-2026-34932.
What can be the consequences of CVE-2026-34932?
The consequences of CVE-2026-34932 can include unauthorized actions being performed on behalf of the user, leading to potential data breaches.