Aikido Attack finds multiple 0-days in Hoppscotch
aikido.dev | research | #ai-security | #zero-day | #account-takeover | #xss | #ai-pentesting | #open-redirect | #hoppscotch
Summary
AI pentest agents found three 0-days in the open source API platform Hoppscotch: open redirect to account takeover, stored XSS via mock server, and broken access control—patched in 2026.3.0.
- Published
- Collected
Skip to content