The CVE-2026-59721 record was published on 2026-07-09T18:16:57.200Z. Hoppscotch, an open source API development ecosystem, has a vulnerability in its updateInfraConfigs GraphQL mutation that allows an attacker to execute arbitrary commands as root in the backend container. This issue is fixed in version 2026.6.0. The NVD entry for this CVE is currently Deferred.
CVE-2026-59720 is a high-severity vulnerability in Hoppscotch, an open-source API development ecosystem. Prior to version 2026.6.0, mock server creation did not persist the isPublic input field, causing mock servers linked to private collections to be publicly accessible without authentication. This could potentially expose sensitive API data. The issue is fixed in version 2026.6.0. Security teams and dev [truncated]