Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6vr3-7wcx-v5g5 | browserstack-runner vulnerable to Remote Code Execution via vm sandbox escape in _log HTTP handler |
Wed, 03 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Browserstack
Browserstack browserstack-runner |
|
| Vendors & Products |
Browserstack
Browserstack browserstack-runner |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows unauthenticated network-adjacent attackers to execute arbitrary code by submitting crafted JSON request bodies to the handler, which passes user-supplied data to vm.runInNewContext() combined with eval(). Attackers can escape the Node.js vm sandbox by leveraging a host-context Function reference through util.format to access the host process via this.constructor.constructor, achieving full remote code execution on the underlying system without any authentication. | |
| Title | BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-03T14:02:38.017Z
Reserved: 2026-05-27T17:40:12.739Z
Link: CVE-2026-49143
Updated: 2026-06-03T14:02:28.593Z
Status : Deferred
Published: 2026-06-02T21:16:28.070
Modified: 2026-06-04T16:10:59.820
Link: CVE-2026-49143
No data.
OpenCVE Enrichment
Updated: 2026-06-03T10:54:47Z
Github GHSA