CVE-2026-59721Patch

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in utils.ts permits path, query, or fragment content that nodemailer parses into sendmail transport options, allowing an admin to execute arbitrary commands as root in the backend container after restart and mail sending. This issue is fixed in version 2026.6.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78CWE-915

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-10: 2Patch / Workaround · 2026-07-10: 2Technical Details · 2026-07-10: 207-10
Signal classification1 categories
Patch
2100.0%
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-59721 - OS Command Injection in Hoppscotch. CVSS 7.2. Admin can execute arbitrary commands as root via SMTP config. Upgrade to 2026.6.0 immediately. #CVE #Hoppscotch #infosec #devsecops #devops #cvealert #developers #sysadmin #linux

    Post summary

    Auth0 discovered an OS Command Injection (CVE-2026-59721) in Hoppscotch with a CVSS score of 7.2; administrators are urged to upgrade immediately to version 2026.6.0 to mitigate the risk.

    100221.1K
    1.0K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-59721 - OS Command Injection in #Hoppscotch. #CVSS 7.2. Admin can execute arbitrary commands as root via #SMTP config. Upgrade to 2026.6.0 immediately. #CVE #DevSecOps #devops #developers #sysadmin #git #github #gitlab #cybernews #infosec

    Post summary

    The tweet announces an OS Command Injection vulnerability in Hoppscotch, warns that administrators can run arbitrary commands as root, and urges an immediate upgrade to version 2026.6.0 to mitigate the issue.

    1000057
    975 followersView on X

Explore more