Junglewise Threat Intelligence

CVE-2026-49144: BrowserStack Runner path traversal in lib/server.js

CVE-2026-49144 · Severity: medium · CVSS 6.5 · Published 2026-06-02

Executive brief

browserstack-runner is a tool used to run BrowserStack tests from the command line. A security flaw in its internal web server allows anyone on the same network to read sensitive files from the computer running the tests without needing a password. This could lead to the theft of BrowserStack login keys, source code, and system configuration files.

Technical details

The vulnerability exists in the `_default` handler within `lib/server.js`. The handler uses `path.join(process.cwd(), uri)` to resolve file paths from incoming request URLs without validating that the resulting path remains within the intended project directory. Because the server binds to `0.0.0.0` by default and lacks authentication, a network-adjacent attacker can use `../` sequences to traverse the file system. This allows for the disclosure of sensitive files such as `browserstack.json` (containing cleartext credentials), SSH keys, and system files like `/etc/passwd`. As of the advisory date, no patched version is available; users are advised to manually implement path validation or restrict the server to bind only to `127.0.0.1`.

Affected products

  • BrowserStack browserstack-runner <= 0.9.5

Timeline

  • 2026-05-27: disclosed
  • 2026-06-02: advisory: NVD publication date
  • 2026-06-03: advisory: GitHub Advisory reviewed

References

Related threats