Path Traversal in @logto/tunnel Service
The @logto/tunnel package (v0.3.8 and earlier) is vulnerable to a path traversal attack allowing unauthenticated, remote read access to local files via improper URL sanitization.
CVE search metadata
CVE search record: CVE-2026-63188. KEV: no. Product: @logto/tunnel. Brief: Path Traversal in @logto/tunnel Service. Brief link: https://feed.craftedsignal.io/briefs/2026-08-logto-tunnel-traversal/
The @logto/tunnel CLI tool, commonly used for testing Logto sign-in experiences, contains a high-severity path traversal vulnerability tracked as CVE-2026-63188. The vulnerability resides in the static asset proxy implementation within packages/tunnel/src/commands/tunnel/utils.ts. When the tunnel is started with the --experience-path flag, the application serves files from this directory using a proxy that fails to validate or normalize incoming request URLs.
By crafting a request containing directory traversal sequences (e.g., ../), an unauthenticated network actor can escape the intended static file root. Because the server uses path.join to resolve the final filesystem path without subsequent containment checks, it directly accesses any file readable by the user process running the tunnel. This is particularly critical when the tunnel is exposed to network interfaces, allowing attackers to exfiltrate local configuration, development environment secrets, or sensitive files from the host machine.
Attack Chain
- The target deploys a Logto tunnel service using the
logto-tunnelCLI and specifies a custom UI directory via the--experience-pathoption. - The service binds to a network port (e.g., 9000) on all interfaces, exposing the static proxy functionality.
- An attacker identifies the accessible tunnel port via network scanning or local internal reconnaissance.
- The attacker crafts an HTTP request to the tunnel port with a path containing traversal sequences, such as
GET /../../etc/passwd HTTP/1.1. - The
packages/tunnel/src/commands/tunnel/utils.tsmodule receives the request and appends the malicious URL directly to the basestaticPathusingpath.join. - The application performs an
fs.opencall on the resulting path, successfully resolving to a file outside the designated root. - The tunnel service returns the contents of the requested file in the HTTP response body to the attacker.
Impact
Successful exploitation allows unauthenticated remote attackers to read arbitrary files from the filesystem of the host running logto-tunnel. In development environments where this tool is typically deployed, this can lead to the exfiltration of credentials, API keys, and sensitive project configuration files.
Recommendation
- Update
@logto/tunnelto a version containing the patch for CVE-2026-63188. - Restrict network access to the tunnel service by binding only to
localhost(127.0.0.1) if remote access is not required for testing. - Enable web server logs to monitor for requests containing path traversal sequences (
../) targeting the tunnel port. - Use network access control lists (ACLs) to block external or unauthorized internal connections to the configured tunnel port.
Immediate actions
Update @logto/tunnel to latest version to remediate CVE-2026-63188.
Mitigations
Ensure logto-tunnel is bound to localhost only (127.0.0.1) to limit exposure.
CVE-2026-63188