MEDIUM6.5npm
GHSA-8wqc-v2q8-vff2· CVE-2026-59149@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
Modified: 9/11/2026
package
pkg:npm/%40mockoon/commons-server
@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
Modified: 9/11/2026
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
Modified: 9/11/2026
Mockoon has a Path Traversal and LFI in the static file serving endpoint
Modified: 9/13/2025