THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rqx4-3f6q-3x2v (high) — @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft

[GHSA] GHSA-rqx4-3f6q-3x2v (high) — @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft

highgithub_advisoriesPublished 2026-09-11

GHSA-rqx4-3f6q-3x2v Severity: high CVE: CVE-2026-59148

@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft

## Summary

Mockoon's admin API (`commons-server/src/libs/server/admin-api.ts`) is mounted on the same Express listener as the use

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rqx4-3f6q-3x2v