CVE-2026-49144: Browserstack Browserstack-Runner

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. Attackers can exploit the unauthenticated HTTP server bound on all interfaces to traverse outside the project root and access sensitive files.

Affected products

Published 2026-06-02. Last modified 2026-10-08.