CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-63188

CVE-2026-63188: Unauthenticated Directory Traversal in @logto/tunnel

Alon Barad
Alon Barad
Software Engineer

Aug 19, 2026·7 min read·26 visits

Executive Summary (TL;DR)

Unauthenticated remote directory traversal in @logto/tunnel < 0.3.9 allows arbitrary file read via crafted GET requests when custom experience hosting is enabled.

A high-severity path traversal vulnerability exists in the @logto/tunnel npm package (part of the Logto repository) prior to version 0.3.9. Remote unauthenticated attackers can exploit this vulnerability to read arbitrary local files by sending crafted HTTP requests with directory traversal sequences when the static file proxy is active.

Vulnerability Overview

Logto serves as an open-source identity and access management system designed for modern multi-tenant environments. To facilitate custom sign-in flows, Logto contains a tunnel utility (@logto/tunnel) that allows developers to run a local static asset server for testing personalized web assets. When initialized, this tunnel exposes an interface through which clients can request custom HTML pages, stylesheets, and JavaScript files directly from a designated local workspace.

The exposure is located inside the static file proxy implementation within the @logto/tunnel package. When processing static asset requests, the tunnel service accepts the request path from the incoming HTTP transaction. Because this proxy function failed to isolate requests within the specified root directory, it opened an unauthenticated attack surface.

An attacker who can reach this proxy port can supply directory traversal sequences in the requested path. This enables the retrieval of sensitive filesystem objects. The vulnerability is cataloged as CVE-2026-63188 and carries a High severity CVSS v4.0 base score of 8.7.

Root Cause Analysis

The root cause of CVE-2026-63188 lies in the programmatic construction of filesystems paths using raw, unvalidated HTTP request paths. In vulnerable versions of @logto/tunnel prior to 0.3.9, the local server implemented static asset serving by resolving paths directly via Node.js native path modules. Specifically, the request route logic used request.url to match files within the directory provided by the --experience-path argument.

When an HTTP client executes a request, the request.url property contains the path portion of the request URL. In a secure static server implementation, this input must be treated as untrusted and normalized, percent-decoded, and validated to ensure it cannot escape the static root. However, the vulnerable logic directly supplied request.url to path.join.

The path.join utility in Node.js joins all given path segments together and normalizes the resulting path. If the joint path contains relative directory traversal characters such as ../, the utility evaluates these segments lexically. If the input contains a series of traversal segments that exceed the depth of the static root directory, the resolved path ascends beyond the root and references parent directories on the host operating system.

Once the lexical normalization completes, the application utilizes the resulting path string directly in an asynchronous filesystem opening function. Because the application executes no logical validation checking whether the resolved canonical target resides within the boundaries of the defined static directory, the operating system kernel fulfills the request. This exposes any file readable by the process owner.

Code-Level Vulnerability and Fix Analysis

To understand the mechanics of the patch, it is necessary to examine the vulnerable code path inside packages/tunnel/src/commands/tunnel/utils.ts. The vulnerable version processed requests through an unconstrained resolution sequence:

// VULNERABLE CODE PATH
if (request.method === 'HEAD' || request.method === 'GET') {
  const fallBackToIndex = !isFileAssetPath(request.url);
  // Vulnerability: No sanitization of request.url before joining with staticPath
  const requestPath = path.join(staticPath, fallBackToIndex ? index : request.url);
  const { range = '' } = request.headers;
 
  const readFile = async (requestPath: string, start?: number, end?: number) => {
    // Arbitrary file resolution and read
    const fileHandle = await fs.open(requestPath, 'r');
    // ... read and return file data
  };
}

The security remediation introduces the getSafeStaticFilePath helper in commit 5686815955534f803d3d50738259efd0f741e62c to enforce strict logical boundaries. Below is the updated, secure implementation:

// PATCHED CODE PATH
export const getSafeStaticFilePath = (staticPath: string, requestUrl: string) => {
  // Step 1: Isolate the pathname from query and fragment identifiers
  const [pathname = ''] = requestUrl.split(/[#?]/);
  
  // Step 2: Safely percent-decode the pathname to handle obfuscated payloads
  const decodedPathname = trySafe(() => decodeURIComponent(pathname));
 
  // Step 3: Block Windows backslash sequences to prevent bypasses on Windows nodes
  if (!decodedPathname || decodedPathname.includes('\\')) {
    return;
  }
 
  // Step 4: Resolve the configured static path into an absolute canonical path
  const staticRoot = path.resolve(staticPath);
  
  // Step 5: Clean leading slashes from the request path to ensure relative mapping
  const requestPath = decodedPathname.replace(/^\/+/, '');
  
  // Step 6: Generate the final target resolution
  const resolvedPath = path.resolve(staticRoot, requestPath);
  
  // Step 7: Evaluate the relative position of the resolved file versus the root
  const relativePath = path.relative(staticRoot, resolvedPath);
 
  // Step 8: Strict guard - verify if target resolves outside the static boundaries
  if (relativePath.startsWith('..') || path.isAbsolute(relativePath)) {
    return;
  }
 
  return resolvedPath;
};

The introduced fix is robust. By processing path.relative(staticRoot, resolvedPath), the application explicitly measures the logical distance between the authorized root and the resolved target. If the output of path.relative begins with .., it mathematically proves that the targeted resource requires traveling upward from the static root. The inclusion of decodeURIComponent ensures that URL-encoded bypasses such as %2e%2e are decoded prior to calculation, preventing path traversal evasion.

Exploitation Methodology

Exploitation of CVE-2026-63188 is direct and does not require complex orchestration or prior authentication. An attacker must first establish network connectivity to the port exposed by the @logto/tunnel instance. Typically, this service is spawned when developers test localized customization flows, but if bound to wildcards (0.0.0.0), the port becomes accessible on local area networks or public addresses.

Once connectivity is confirmed, the attacker constructs HTTP GET requests containing directory traversal sequences. When using common utilities like curl, standard client-side path normalization will automatically resolve traversal sequences before transmission. Therefore, the attacker must supply the --path-as-is command-line flag or execute the request via raw socket streams.

# Standard exploitation targeting POSIX system files
curl --path-as-is http://target-host:3000/../../../../../../etc/passwd
# Evasion attempt targeting Node.js execution on a Windows host
curl --path-as-is http://target-host:3000/..\\..\\..\\..\\Windows\\win.ini
# Targeted extraction of local application dependencies and configuration structures
curl --path-as-is http://target-host:3000/../package.json

Upon receiving these payloads, the server processes the traversal input. Since the server lacks validating checks, it attempts to open the corresponding OS path. The server then responds with an HTTP status code 200 and the content of the targeted system file in the response body.

Impact Assessment

The impact of this path traversal vulnerability is significant. While @logto/tunnel is primarily positioned as a development utility, developers often execute these services within cloud containers, staging instances, or local production systems. If the service is running with high OS-level privileges (such as root or Administrator), the entire filesystem becomes accessible to unauthenticated remote attackers.

Through arbitrary file read capabilities, attackers can exfiltrate sensitive files, including system secrets, configuration maps, environment variables containing API keys, database credentials, and SSH private keys. In modern microservice and cloud architectures, the leak of a single configuration file or environment block can allow an attacker to pivot and compromise entire cloud networks.

Additionally, reading application source code or operational metadata permits attackers to map out vulnerabilities inside surrounding software components. Since no write access is granted directly via this directory traversal, the impact is confined to high confidentiality loss (VC:H), while integrity (VI:N) and availability (VA:N) remain unaffected.

Detection and Remediation

The primary and recommended mitigation for CVE-2026-63188 is upgrading @logto/tunnel to version 0.3.9 or higher. This upgrade ensures that the getSafeStaticFilePath helper actively validates and rejects traversal patterns before files are accessed. If immediate updates are not feasible, several defensive controls can be implemented to minimize risk.

First, modify the launch parameters of the tunnel utility to bind specifically to the loopback interface (127.0.0.1 or ::1) instead of the wildcard address. This limits exploitation capabilities to local processes on the host. Network access control lists or host-based firewall configurations must be configured to drop any inbound external packets directed at the tunnel ports.

For network detection, network intrusion detection systems (NIDS) can monitor traffic for suspicious traversal requests. Security engineers can also deploy Web Application Firewalls (WAF) to inspect incoming request paths and block requests containing relative path segments. Finally, running host-based file monitoring tools can help identify unauthorized reads to critical directories such as /etc or directory structural locations outside of web workspaces.

Official Patches

logto-ioLogto Security Advisory GHSA-rxjr-6c9q-h67x
logto-ioFix Pull Request
logto-ioFix Commit

Fix Analysis (1)

Technical Appendix

CVSS Score
8.7/ 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Systems

@logto/tunnel < 0.3.9Logto deployments containing @logto/tunnel packages < 0.3.9

Affected Versions Detail

Product
Affected Versions
Fixed Version
@logto/tunnel
logto-io
< 0.3.90.3.9
AttributeDetail
CWE IDCWE-22
Attack VectorNetwork (AV:N)
CVSS Score8.7 (High)
Exploit StatusProof-of-Concept
KEV StatusNot Listed
ImpactUnauthenticated Arbitrary File Read (Confidentiality: High)

MITRE ATT&CK Mapping

T1083File and Directory Discovery
Discovery
T1005Data from Local System
Collection
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Vulnerability Timeline

Official patch code developed and committed to Logto main repository
2026-06-30
GitHub Security Advisory GHSA-rxjr-6c9q-h67x published
2026-08-19
CVE-2026-63188 assigned and synchronized with NVD
2026-08-19

References & Sources

  • [1]GitHub Security Advisory (GHSA-rxjr-6c9q-h67x)
  • [2]Official Pull Request #9113
  • [3]Security Patch Commit
  • [4]Logto Tunnel v0.3.9 Release Page

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-105852
5.3

CVE-2026-105852: Authorization Bypass and Related-Document Oracle in Payload CMS

An authorization bypass vulnerability in Payload CMS enables unauthenticated attackers to query and infer the existence of restricted documents via nested relationship queries on public collections. This cross-document contamination flaw affects both MongoDB and Drizzle SQL database adapters, allowing unauthorized reads of relationship metadata.

Amit Schendel
Amit Schendel
1 views•6 min read
•about 2 hours ago•CVE-2026-105850
8.8

CVE-2026-105850: Race Condition and Order Double-Processing in @payloadcms/plugin-ecommerce

A high-severity race condition vulnerability exists in @payloadcms/plugin-ecommerce within the Stripe payment adapter's order confirmation pipeline. Unauthenticated attackers or parallel webhook deliveries can exploit sequential, non-atomic database operations to bypass state verifications, leading to duplicate order creation, multiple inventory decrements, and inconsistent database records.

Amit Schendel
Amit Schendel
5 views•7 min read
•about 3 hours ago•CVE-2026-105849
7.7

CVE-2026-105849: Sensitive Data Exposure and Privilege Escalation in Payload CMS API Key Authentication

A sensitive data exposure vulnerability in Payload CMS allows authenticated low-privilege users to retrieve decrypted, plaintext API keys of other users, including administrators, leading to full administrative account takeover and privilege escalation.

Amit Schendel
Amit Schendel
7 views•5 min read
•about 4 hours ago•CVE-2026-86540
8.5

CVE-2026-86540: Arbitrary Code Execution via LSP Binary Override in knowns

CVE-2026-86540 is a high-severity arbitrary code execution vulnerability in knowns, a repository management tool. The vulnerability occurs when the application parses and executes unvalidated language server binary overrides defined within a project's local configuration file.

Amit Schendel
Amit Schendel
8 views•5 min read
•about 5 hours ago•CVE-2026-105854
8.7

CVE-2026-105854: Regular Expression Denial of Service (ReDoS) and Uncontrolled Resource Consumption in Payload CMS

Payload CMS, a popular open-source headless Content Management System, contains a critical Regular Expression Denial of Service (ReDoS) and uncontrolled resource consumption vulnerability in versions prior to 3.90.0 and canary versions prior to 4.0.0-canary.34. Due to nested quantifiers in the multipart boundary regex validation pattern, and the absence of streaming backpressure controls, remote attackers can trigger catastrophic backtracking and memory exhaustion. This blocks the single-threaded Node.js event loop, resulting in a persistent and complete Denial of Service (DoS).

Amit Schendel
Amit Schendel
7 views•6 min read
•about 6 hours ago•CVE-2026-105855
7.6

CVE-2026-105855: Privilege Escalation via Improper Access Control on Password Fields in Payload CMS

An Improper Access Control vulnerability (CWE-284) in Payload CMS prior to version 3.90.0 and 4.0.0-canary.34 allows authenticated, low-privileged users to bypass field-level access control restrictions and overwrite the password of other accounts, leading to complete account takeover and privilege escalation.

Alon Barad
Alon Barad
10 views•6 min read