CVE-2025-59049 is a path traversal and local file inclusion (LFI) vulnerability in Mockoon versions prior to 9.2.0, allowing an unauthenticated attacker to read any file on the mock server's filesystem by manipulating static file serving configurations. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with no user interaction required, potentially leading to significant information disclosure. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists, and its FAUCET Risk Score of 93/100 indicates a high potential for impact, especially in cloud environments. Community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mockoon | Mockoon | < 9.2.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.