Executive brief
browserstack-runner is a tool used to run BrowserStack tests from the command line. A security flaw in its internal web server allows anyone on the same network to read sensitive files from the computer running the tests without needing a password. This could lead to the theft of BrowserStack login keys, source code, and system configuration files.
Technical details
The vulnerability exists in the `_default` handler within `lib/server.js`. The handler uses `path.join(process.cwd(), uri)` to resolve file paths from incoming request URLs without validating that the resulting path remains within the intended project directory. Because the server binds to `0.0.0.0` by default and lacks authentication, a network-adjacent attacker can use `../` sequences to traverse the file system. This allows for the disclosure of sensitive files such as `browserstack.json` (containing cleartext credentials), SSH keys, and system files like `/etc/passwd`. As of the advisory date, no patched version is available; users are advised to manually implement path validation or restrict the server to bind only to `127.0.0.1`.
Affected products
- BrowserStack browserstack-runner <= 0.9.5
Timeline
- 2026-05-27: disclosed
- 2026-06-02: advisory: NVD publication date
- 2026-06-03: advisory: GitHub Advisory reviewed