
CVE-2026-30825 hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authenticated user to delet… https://www.cve.org/CVERecord?id=CVE-2026-30825
Post summary
The post announces CVE-2026-30825 against Hoppscotch, detailing a DELETE endpoint that permits authenticated users to delete access tokens and noting the fix in version 2026.2.1.
