Description
BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. Attackers can exploit the unauthenticated HTTP server bound on all interfaces to traverse outside the project root and access sensitive files.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version
Credits
Christ Bouchuen
References
github.com/...runner/security/advisories/GHSA-8rpw-6cqh-2v9h
github.com/...runner/security/advisories/GHSA-8rpw-6cqh-2v9h
www.vulncheck.com/...path-traversal-via-default-http-handler