Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Risingzero

#37616of 53,608
7.5Total CVSS
Vulnerabilities · 1
PT-2025-37089
7.5
2025-03-11
Mockoon · Mockoon · CVE-2025-59049
Name of the Vulnerable Software and Affected Versions: Mockoon versions prior to 9.2.0 Description: Mockoon is a tool used to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving generates the server filename from user input, which is vulnerable to Path Traversal and Local File Inclusion (LFI). This allows an attacker to access any file within the mock server filesystem. The issue may be particularly relevant in cloud-hosted server instances. Recommendations: Update to version 9.2.0 or later.