PatchSiren

mockoon CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM mockoon CVE published 2026-07-09

CVE-2026-59149

CVE-2026-59149 is a medium-severity vulnerability in Mockoon, a tool for designing and running mock APIs. The issue allows an unauthenticated client to read files from sibling paths outside the served directory through HTTP sendFile, WebSocket, or callbacks. This is due to a flawed prefix test in the getSafeFilePath function, which does not properly validate path separators, permitting a ../-escaped path [truncated]

HIGH mockoon CVE published 2026-07-09

CVE-2026-59148

The CVE record for CVE-2026-59148 was published on 2026-07-09T19:17:07.067Z and has not been modified since then. The NVD entry is currently Deferred. This vulnerability affects Mockoon versions prior to 9.7.0, allowing unauthenticated callers to read environment variables, write arbitrary process environment variables, rewrite mock route bodies, statuses, and headers, read transaction logs and SSE stream [truncated]