All 3 CVE vulnerabilities found in mockoon, with AI-generated Chinese analysis, references, and POCs.
Vendor: mockoon
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-59149 | Mockoon: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check) CWE-22 | 6.5 | Medium | 2026-07-09 |
| CVE-2026-59148 | Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft CWE-306 | 8.8 | High | 2026-07-09 |
| CVE-2025-59049 | Mockoon has a Path Traversal and LFI in the static file serving endpoint CWE-73 | 7.5 | High | 2025-09-10 |
All 3 known CVE vulnerabilities affecting mockoon with full Chinese analysis, references, and POCs where available.