CVE 7.1 HIGH

BrowserStack Runner 0.9.5 Path Traversal via _default HTTP Handler_CVE-2026-49144

7.1 / 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. Attackers can exploit the unauthenticated HTTP server bound on all interfaces to traverse outside the project root and access sensitive files.

Basic Information

ID CVE-2026-49144
Source VulnCheck
Published Jun 2, 2026 at 20:34

Affected Product

Vendor browserstack
Product browserstack-runner
Affected Versions browserstack browserstack-runner 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.