CVE-2026-49144

BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. Attackers can exploit the unauthenticated HTTP server bound on all interfaces to traverse outside the project root and access sensitive files.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-02 21:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-49144

Mitre link : CVE-2026-49144

CVE.ORG link : CVE-2026-49144


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')