Autonomous AI Agent Finds CVSS 10.0 Full Compromise in Hoppscotch (opens in new tab)
### Summary The `POST /v1/onboarding/config` endpoint allows an unauthenticated attacker to inject arbitrary `InfraConfig` keys -- including `JWT_SECRET` and `SESSION_SECRET` -- into the databa...
Read the original article