CVE-2026-59149 is a medium-severity vulnerability in Mockoon, a tool for designing and running mock APIs. The issue allows an unauthenticated client to read files from sibling paths outside the served directory through HTTP sendFile, WebSocket, or callbacks. This is due to a flawed prefix test in the getSafeFilePath function, which does not properly validate path separators, permitting a ../-escaped path [truncated]
The CVE record for CVE-2026-59148 was published on 2026-07-09T19:17:07.067Z and has not been modified since then. The NVD entry is currently Deferred. This vulnerability affects Mockoon versions prior to 9.7.0, allowing unauthenticated callers to read environment variables, write arbitrary process environment variables, rewrite mock route bodies, statuses, and headers, read transaction logs and SSE stream [truncated]