7.1
/ 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. Attackers can exploit the unauthenticated HTTP server bound on all interfaces to traverse outside the project root and access sensitive files.
Basic Information
ID
CVE-2026-49144
Source
VulnCheck
Published
Jun 2, 2026 at 20:34
Affected Product
Vendor
browserstack
Product
browserstack-runner
Affected Versions
browserstack browserstack-runner 0