THREAT OPS › Threat News › [GHSA] GHSA-rqx4-3f6q-3x2v (high) — @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
[GHSA] GHSA-rqx4-3f6q-3x2v (high) — @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
GHSA-rqx4-3f6q-3x2v Severity: high CVE: CVE-2026-59148
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
## Summary
Mockoon's admin API (`commons-server/src/libs/server/admin-api.ts`) is mounted on the same Express listener as the use
MITRE ATT&CK techniques
- ServerlessT1583.007
- JavaScriptT1059.007
- ServerlessT1584.007
- ServerlessAML.T0008.004
Indicators of compromise
- CVE-2026-59148cve
- http://127.0.0.1:3100/users/42url
- http://127.0.0.1:3100/mockoon-admin/env-vars/API_KEYurl
- http://127.0.0.1:3100/mockoon-admin/env-varsurl
- https://attacker.evil`url
- https://attacker.evilurl
- http://127.0.0.1:3100/mockoon-admin/environmenturl
- http://127.0.0.1:3100/users/99url
- http://127.0.0.1:3100/mockoon-admin/logs?limit=2url
- http://127.0.0.1:3100/mockoon-admin/state/purgeurl
Original source: https://github.com/advisories/GHSA-rqx4-3f6q-3x2v