Unauthenticated Admin API Vulnerability in @Mockoon/commons-server
A critical vulnerability (CVE-2026-59148) in @Mockoon/commons-server allows unauthenticated attackers to hijack mock-state, steal secrets, and poison environment variables due to a lack of authentication and wildcard CORS configuration. The vulnerability affects multiple deployments, including commons-server, CLI, and serverless. Immediate patching is recommended.