CVE-2026-69189

Source
https://cve.org/CVERecord?id=CVE-2026-69189
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-69189.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-69189
Aliases
  • GHSA-p25p-g9jp-7q46
Published
2026-08-18T15:05:10Z
Modified
2026-08-20T03:55:02Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L CVSS Calculator
Summary
Hoppscotch: Cross-user private data exposure and UserHistory IDOR via team GraphQL resolvers
Details

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. This issue is fixed in version 2026.6.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200",
        "CWE-639",
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69189.json"
}
References

Affected packages

Git / github.com/hoppscotch/hoppscotch

Affected ranges

Type
GIT
Repo
https://github.com/hoppscotch/hoppscotch
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2026.6.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2023.*
2023.12.0
2023.12.1
2023.12.2
2023.12.3
2023.4.0
2023.4.1
2023.4.2
2023.4.3
2023.4.4
2023.4.5
2023.8.0
2023.8.1
2023.8.2
2024.*
2024.10.0
2024.10.1
2024.11.0
2024.12.0
2024.12.1
2024.12.2
2024.3.0
2024.3.1
2024.3.2
2024.3.3
2024.6.0
2024.7.0
2024.7.1
2024.8.0
2024.8.1
2024.8.2
2024.8.3
2024.9.0
2024.9.1
2024.9.2
2025.*
2025.1.0
2025.1.1
2025.10.0
2025.10.1
2025.11.0
2025.11.1
2025.11.2
2025.12.0
2025.12.1
2025.2.0
2025.2.1
2025.3.0
2025.3.1
2025.3.2
2025.4.0
2025.5.0
2025.5.1
2025.6.0
2025.6.1
2025.7.0
2025.7.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
2025.9.2
2026.*
2026.1.0
2026.1.1
2026.2.0
2026.2.1
2026.3.0
2026.3.1
2026.4.0
2026.5.0
v0.*
v0.1.0
v1.*
v1.0.0
v1.10.0
v1.12.0
v1.5.0
v1.9.0
v1.9.5
v1.9.7
v1.9.9
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.2.1
v3.*
v3.0.0
v3.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-69189.json"