PT-2025-37089 · Mockoon · Mockoon

Risingzero

·

Published

2025-03-11

·

Updated

2025-10-08

·

CVE-2025-59049

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mockoon versions prior to 9.2.0
Description: Mockoon is a tool used to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving generates the server filename from user input, which is vulnerable to Path Traversal and Local File Inclusion (LFI). This allows an attacker to access any file within the mock server filesystem. The issue may be particularly relevant in cloud-hosted server instances.
Recommendations: Update to version 9.2.0 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-59049
GHSA-W7F9-WQC4-3WXR

Affected Products

Mockoon