CVE-2026-63188Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy from packages/tunnel/src/commands/tunnel/index.ts and passed request.url from static asset requests through packages/tunnel/src/commands/tunnel/utils.ts using path.join(staticPath, request.url) and then fs.open(requestPath, "r") without URL normalization or a containment check. When --experience-path was enabled and the tunnel port was reachable, an unauthenticated requester could send a path containing ../ to createStaticFileProxy and read files outside the configured static directory that were readable by the logto-tunnel process. The service used server.listen(port), which could expose the tunnel to other hosts depending on the platform and deployment. This issue is fixed in version 0.3.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-20: 2Technical Details · 2026-08-20: 208-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Logto Tunnel, Path Traversal, #CVE-2026-63188 (High) -DC-Aug2026-1662 https://dailycve.com/logto-tunnel-path-traversal-cve-2026-63188-high-dc-aug2026-1662/

    Post summary

    A high severity Path Traversal vulnerability (CVE-2026-63188) has been announced for Logto Tunnel.

    0000025
    229 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-63188 Logto Tunnel Path Traversal Allows Reading Arbitrary Files https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-63188

    Post summary

    CVE-2026-63188 is a path traversal flaw in Logto Tunnel that lets attackers read any file; no PoC, exploit or patch information is provided.

    00000115
    4.1K followersView on X

Explore more