THREAT OPS › Threat News › [GHSA] GHSA-rxjr-6c9q-h67x (high) — logto-tunnel serves files outside --experience-path via path traversal
[GHSA] GHSA-rxjr-6c9q-h67x (high) — logto-tunnel serves files outside --experience-path via path traversal
GHSA-rxjr-6c9q-h67x Severity: high CVE: CVE-2026-63188
logto-tunnel serves files outside --experience-path via path traversal
### Summary
`@logto/tunnel` serves custom sign-in experience files from the `--experience-path` directory. When the tunnel service is reachable, a requester can use `../` path segments in a static asset request to read files outside that directory that the CLI process ca
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-63188cve
Original source: https://github.com/advisories/GHSA-rxjr-6c9q-h67x