Medium · 5.4 Node.js & npm GHSA-rqx4-3f6q-3x2v CVE-2026-59148 GHSA-8wqc-v2q8-vff2 CVE-2026-59149
Mockoon Admin API Flaws: Unauthenticated Secret Theft, Mock Hijack, and Path Traversal
Two vulnerabilities in Mockoon's commons-server and CLI packages let unauthenticated attackers read and overwrite environment secrets, rewrite mock API responses, and read files outside the served directory. Both are fixed in version 9.7.0.
AI summary
Mockoon, a popular open-source API mocking tool distributed as the @mockoon/commons-server library, the @mockoon/cli command-line tool, and a serverless wrapper, is affected by two vulnerabilities disclosed together. The first, CVE-2026-59148, concerns an administrative API that is enabled by default, exposed without any authentication, and served with permissive cross-origin headers. The second, CVE-2026-59149, is a path traversal flaw in how the server resolves file paths for templated file responses. Both issues were published on 2026-09-11 and are fixed in version 9.7.0.
What happened
Two distinct vulnerabilities were identified in Mockoon's server components. CVE-2026-59148 affects the admin API that Mockoon mounts alongside user-defined mock routes. This admin API is enabled by default in @mockoon/commons-server, @mockoon/cli, and the serverless wrapper, has no authentication mechanism of any kind, and responds with Access-Control-Allow-Origin: * on every endpoint, permitting GET, POST, PUT, PATCH, DELETE and other methods. The default hostname setting ('') causes the server to bind to all network interfaces (0.0.0.0) rather than localhost only. CVE-2026-59149 is a separate path traversal issue: when a FILE response uses a templated filePath (for example, based on a query parameter), the function that checks whether the resolved path stays within the intended base directory uses a simple string-prefix comparison rather than a proper path-boundary check. A crafted request using '../' sequences can resolve to a sibling directory whose absolute path happens to begin with the same string as the intended base directory, allowing files outside the served directory to be read.
Technical cause
For CVE-2026-59148, the root cause is threefold: the admin API defaults to enabled (enableAdminApi: true) across all three runtime packages; the admin API's CORS middleware unconditionally sets a wildcard origin and allows state-changing HTTP methods; and the endpoint handler that writes environment variables performs no validation on which keys may be set, allowing any process.env key to be overwritten. Combined with the default hostname binding to all interfaces, this exposes the admin API to any party that can reach the configured port, and in local-development scenarios, to malicious websites via cross-origin requests from a browser. For CVE-2026-59149, the getSafeFilePath function bounds a resolved file path using resolvedPath.startsWith(staticBaseDir) without appending a path separator or verifying a proper relative-path boundary. A path such as '/srv/public_backup/.env' passes this check against a base directory of '/srv/public' because the string 'public_backup' begins with 'public'.
Why it matters
Mockoon is widely used for local development, CI pipelines, and staging environments to simulate APIs. Because the admin API in CVE-2026-59148 is enabled by default and unauthenticated, any party able to reach the mock server's port (which binds to all interfaces by default) can read environment variables used as secrets in mock templates, overwrite arbitrary process environment variables including credentials consumed by the surrounding runtime, rewrite the body, status code, and headers of every mock route at runtime (affecting downstream consumers such as frontend dev servers, CI test suites, or integration partners), read transaction logs containing consumers' request bodies and authorization headers, and purge server state. The wildcard CORS configuration also means these actions can be triggered cross-origin from a malicious website visited by a developer while the mock server is running locally. CVE-2026-59149 separately allows an unauthenticated client to read files outside the directory intended to be served, when a route uses a templated file path, which can expose unrelated files on the host such as configuration or credential files.
Who is affected
Users of @mockoon/commons-server and @mockoon/cli prior to version 9.7.0 are affected by both vulnerabilities. This includes direct users of the commons-server library, CLI users (including Docker deployments), and the serverless wrapper, which hardcodes the admin API as enabled with no option to disable it in its constructor. Deployments reachable over a network, such as shared CI or staging environments, face the higher severity scenario for CVE-2026-59148 (rated up to 9.4 Critical by the advisory author); local-development use carries the 8.8 High CVSS score reflected in this package. CVE-2026-59149 affects any deployment where a route is configured with a FILE response using a templated filePath.
Affected versions
@mockoon/commons-server and @mockoon/cli are affected by CVE-2026-59148 in all versions prior to 9.7.0. For CVE-2026-59149, both packages are affected up to and including version 9.6.1. Both issues are resolved in version 9.7.0.
Fixes and mitigation
Version 9.7.0 of @mockoon/commons-server and @mockoon/cli addresses both vulnerabilities. The advisory for CVE-2026-59148 suggests that a complete fix should include requiring authentication on the admin API by default, removing the wildcard CORS response on admin endpoints, binding the admin API to loopback by default, and adding proper key-prefix validation when writing environment variables. No further technical detail on the exact fix implemented in 9.7.0 was provided in the fact package beyond the version number itself.
Recommended action
Upgrade @mockoon/commons-server and @mockoon/cli to version 9.7.0 or later as soon as practical. Until upgraded, avoid binding mock servers to all network interfaces (0.0.0.0) and instead restrict them to localhost (127.0.0.1) where possible. Review deployments for network exposure, particularly in shared CI or staging environments, and treat any secrets previously used in Mockoon environment variables as potentially exposed if the server was reachable by untrusted parties. Review routes configured with FILE responses that use templated filePath values and confirm they do not expose sensitive directories.
PatchBriefing score
5.4 / 10 · Medium
Official CVSS: 8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Why this score
CVE-2026-59148 carries a CVSS base score of 8.8 (High), reflecting network attack vector, low attack complexity, no privileges required, but requiring user interaction (such as visiting a malicious website for the cross-origin scenario), with high impact to confidentiality, integrity, and availability. The PatchBriefing score of 5.4 reflects this base score plus a modest increase for the unauthenticated remote nature of the flaw, with no increase for known exploitation, public exploit code, or EPSS data, none of which were present in the fact package. CVE-2026-59149 carries a CVSS base score of 6.5 (Medium), reflecting network attack vector, low complexity, no privileges required, user interaction required, and high confidentiality impact only (no integrity or availability impact). Its PatchBriefing score of 4.2 similarly reflects the base score plus the unauthenticated remote factor.
Affected versions
- @mockoon/commons-server < 9.7.0
- vulnerable
- ≥ 9.7.0
- patched
- @mockoon/cli < 9.7.0
- vulnerable
- ≥ 9.7.0
- patched
- @mockoon/commons-server <= 9.6.1
- vulnerable
- ≥ 9.7.0
- patched
- @mockoon/cli <= 9.6.1
- vulnerable
- ≥ 9.7.0
- patched
Reported fixes
Version 9.7.0 of @mockoon/commons-server and @mockoon/cli addresses both vulnerabilities. The advisory for CVE-2026-59148 suggests that a complete fix should include requiring authentication on the admin API by default, removing the wildcard CORS response on admin endpoints, binding the admin API to loopback by default, and adding proper key-prefix validation when writing environment variables. No further technical detail on the exact fix implemented in 9.7.0 was provided in the fact package beyond the version number itself.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
GitHub Advisory Database database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email