CVE-2026-49144Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. Attackers can exploit the unauthenticated HTTP server bound on all interfaces to traverse outside the project root and access sensitive files.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-02-03); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-02-03: 3Mentions · 2026-06-03: 2Mentions · 2026-06-04: 1Patch / Workaround · 2026-02-03: 1Technical Details · 2026-02-03: 3Technical Details · 2026-06-03: 2Technical Details · 2026-06-04: 102-0306-0306-04
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-033
Disclosure1General1Patch1
2026-06-032
Disclosure2
2026-06-041
Disclosure1
Full discourse6 posts
  • Joel Vázquez Ortiz@_substrg_
    Disclosure

    #infosec #vulnerability #Microsoft CVE-2026-49144 Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, the installer allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. https://nvd.nist.org/vuln/detail/CVE-2026-49144

    Post summary

    The tweet announces a new privilege‑escalation flaw in Notepad++ installer that lets unprivileged users achieve SYSTEM level via insecure executable search paths.

    1000183
    81 followersView on X
  • Joel Vázquez Ortiz@_substrg_
    General

    CVE-2026-49144 An attacker could use social engineering or click jacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory.

    Post summary

    CVE-2026-49144 allows attackers to use social engineering or click‑jacking to co‑install a malicious executable with a legitimate installer.

    1000035
    81 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 browserstack-runner, Path Traversal, #CVE-2026-49144 (Medium) -DC-Jun2026-179 https://dailycve.com/browserstack-runner-path-traversal-cve-2026-49144-medium-dc-jun2026-179/

    Post summary

    A new CVE (CVE‑2026‑49144) for a Path Traversal flaw in BrowserStack Runner has been disclosed with a medium severity rating.

    0000041
    208 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-49144 BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent a… https://www.cve.org/CVERecord?id=CVE-2026-49144 ----- Traducción: CVE-2026-49144 Bro… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-49144, a path traversal vulnerability in BrowserStack Runner 0.9.5, but provides no PoC, exploit code, or patch information.

    0000038
    79 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-49144 BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent a… https://www.cve.org/CVERecord?id=CVE-2026-49144

    Post summary

    An unauthenticated path traversal flaw was disclosed in BrowserStack Runner 0.9.5, affecting the _default HTTP handler in lib/server.js.

    00000194
    57.6K followersView on X
  • Joel Vázquez Ortiz@_substrg_
    Patch

    CVE-2026-49144 Upon running the installer, the attack executes automatically with SYSTEM privileges. This issue has been fixed and will be released in version 8.8.2. Please upgrade your devices as soon as possible. Have a nice day. 😁

    Post summary

    The advisory confirms CVE‑2026‑49144 is fixed in the upcoming 8.8.2 release and urges users to upgrade their devices promptly.

    0000038
    81 followersView on X

Explore more