Two security vulnerabilities affecting Mockoon runtimes have been disclosed and patched in version 9.7.0. The first involves unauthenticated admin API access combined with permissive CORS, and the second is a path traversal in templated file paths due to an incomplete boundary check. Both are resolved and users are strongly encouraged to upgrade immediately.