Cyber Edition[verified]@CyberEditionPatch
The tweet announces a critical CVE (CVE-2026-50160) in Hoppscotch, highlights the vulnerability’s remote takeover potential, and urges users to upgrade to patch version 2026.5.0 immediately.
IntegSec[verified]@integ_secDisclosure
The snippet announces CVE‑2026‑50160, a mass‑assignment vulnerability in Hoppscotch Self‑Hosted onboarding, without providing PoC, exploit details, or patch information.
/r/netsec@_r_netsecDisclosure
The blog post announces CVE‑2026‑50160, detailing four independent weaknesses that collectively lead to a CVSS 10.0 full compromise in Hoppscotch.
Daily CyberSecurity@the_yellow_fallDisclosure
The tweet briefly announces a CVSS 10 mass assignment vulnerability (CVE‑2026‑50160) in Hoppscotch that allows attackers to overwrite JWT secrets, but no PoC, exploit, patch or active exploitation details are provided.
Open Source Security mailing list@oss_securityDisclosure
A high‑severity vulnerability (CVSS 10) was disclosed that allows unauthenticated overwriting of the JWT secret in Hoppscotch. A proof‑of‑concept was included and the issue is fixed in version 2026.5.0.
pdnuclei-bot@pdnuclei_botDisclosure
The post announces CVE-2026-50160, a critical broken authentication flaw in Hoppscotch <= 2026.4.1 via mass assignment of JWT_SECRET, and links to a detection template.
iototsecnews@iototsecnewsPatch
Hoppscotch discovered to have CVE‑2026‑50160, enabling overwriting of JWT_SECRET and forging admin tokens; updating to the latest version is recommended to mitigate the risk.
Jim Nitterauer 🇺🇸@JNitterauerPatch
CVE‑2026‑50160 is a critical mass‑assignment flaw in self‑hosted Hoppscotch installations that allows attackers to take over a server without authentication; a patch is urgently required.