THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rxjr-6c9q-h67x (high) — logto-tunnel serves files outside --experience-path via path traversal

[GHSA] GHSA-rxjr-6c9q-h67x (high) — logto-tunnel serves files outside --experience-path via path traversal

medgithub_advisoriesPublished 2026-08-19

GHSA-rxjr-6c9q-h67x Severity: high CVE: CVE-2026-63188

logto-tunnel serves files outside --experience-path via path traversal

### Summary

`@logto/tunnel` serves custom sign-in experience files from the `--experience-path` directory. When the tunnel service is reachable, a requester can use `../` path segments in a static asset request to read files outside that directory that the CLI process ca

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rxjr-6c9q-h67x