Vendor
The @logto/tunnel package (v0.3.8 and earlier) is vulnerable to a path traversal attack allowing unauthenticated, remote read access to local files via improper URL sanitization.