@mockoon/commons-server
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @mockoon/commons-serverpage 1 of 1
- CVE-2025-59049HIGHCVSS 7.5EG 7.5✓ Fixed in 9.2.02025-09-10
Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving follows the same approach presented in the documentation page, where the server filename is generated via templating…
- CVE-2026-59148HIGHCVSS 8.8EG 8.8✓ Fixed in 9.7.02026-07-09
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtime…
- CVE-2026-59149MEDIUMCVSS 6.5EG 6.5✓ Fixed in 9.7.02026-07-09
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in packages/commons-server/src/libs/server/server.ts with resolvedPath.startsWith(staticBas…
Check whether @mockoon/commons-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @mockoon/commons-server CVEs against the assets you own.
Start Free Scan →