Vulnerability Description
BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. Attackers can exploit the unauthenticated HTTP server bound on all interfaces to traverse outside the project root and access sensitive files.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/browserstack/browserstack-runner/security/advisories/GHSA-8rp
- https://www.vulncheck.com/advisories/browserstack-runner-path-traversal-via-defa
- https://github.com/browserstack/browserstack-runner/security/advisories/GHSA-8rp
FAQ
What is CVE-2026-49144?
CVE-2026-49144 is a vulnerability with a CVSS score of 6.5 (MEDIUM). BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. ...
How severe is CVE-2026-49144?
CVE-2026-49144 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-49144?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.