CVE-2026-63188: logto-tunnel serves files outside --experience-path via path traversal
@logto/tunnel serves custom sign-in experience files from the --experience-path directory. When the tunnel service is reachable, a requester can use ../ path segments in a static asset request to read files outside that directory that the CLI process can read.
References
- github.com/advisories/GHSA-rxjr-6c9q-h67x
- github.com/logto-io/logto/commit/5686815955534f803d3d50738259efd0f741e62c
- github.com/logto-io/logto/pull/9113
- github.com/logto-io/logto/releases/tag/@logto/tunnel@0.3.9
- github.com/logto-io/logto/security/advisories/GHSA-rxjr-6c9q-h67x
- nvd.nist.gov/vuln/detail/CVE-2026-63188
Code Behaviors & Features
Detect and mitigate CVE-2026-63188 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →