PatchSiren

Browserstack CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH browserstack CVE published 2026-06-15

CVE-2026-48723

CVE-2026-48723 is a HIGH-severity vulnerability in the browserstack-cypress-cli, a command-line interface for running Cypress tests on BrowserStack. The vulnerability, which has a CVSS score of 7.8, allows for OS command injection via the cypress_config_file configuration parameter. This is possible because the loadJsFile() function in readCypressConfigUtil.js constructs a shell command by interpolating t [truncated]

HIGH Browserstack CVE published 2026-01-28

CVE-2025-57283

CVE-2025-57283 is a high-severity command injection vulnerability in the Node.js package browserstack-local 1.5.8. The vulnerability occurs because the logfile variable is not properly sanitized in lib/Local.js. This allows an attacker to inject arbitrary commands, potentially leading to a compromise of the affected system. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.8 [truncated]