Hoppscotch <= 2026.2.1 is vulnerable to a DOM-based open redirect on the /enter page. The redirect query parameter is passed directly to windowz location.href with no origin validation. Requires one additional query parameter to trigger. Exploited via a crafted URL such as /enter?redirect=evil.com&foo=bar.
id: CVE-2026-34847
info:
name: Hoppscotch <= 2026.2.1 - Open Redirect
author: ritikchaddha
se
...