Executive brief
Mockoon is a popular API mocking tool that allows developers to define mock HTTP responses, including serving files. When configured to let users specify filenames via query parameters or URL paths, the application fails to properly validate file paths. An attacker can use path traversal sequences (like `../`) to read arbitrary files from sibling directories outside the intended served directory, potentially exposing sensitive configuration files, environment variables, or customer data.
Technical details
The vulnerability exists in `packages/commons-server/src/libs/server/server.ts` in the `getSafeFilePath` function (line 2315+). When a FILE response is configured with a templated filePath like `/srv/public/{{queryParam 'name'}}`, the function parses request-controlled parameters via TemplateParser and validates the resolved path using `resolvedPath.startsWith(staticBaseDir)`. This check lacks path-separator boundaries—for example, `/srv/public_backup/.env` string-prefixes `/srv/public` and passes validation, even though it lies outside the intended `/srv/public/` directory. The vulnerability affects HTTP sendFile, WebSocket file delivery, and callback responses. An unauthenticated attacker can read arbitrary files by supplying malicious filePath parameters. The patch (version 9.7.0) corrects the boundary check by appending a path separator or using proper relative-path validation.
Affected products
- Mockoon @mockoon/commons-server <= 9.6.1
- Mockoon @mockoon/cli <= 9.6.1
Timeline
- 2026-06-22: disclosed: Initially published by GitHub Advisory Database
- 2026-06-22: patched: Fix released in version 9.7.0
- 2026-09-11: advisory: GHSA-8wqc-v2q8-vff2 and CVE-2026-59149 published