PT-2026-24254 · Oneuptime · Oneuptime
Iconnnjka
·
Published
2026-03-10
·
Updated
2026-03-17
·
CVE-2026-30958
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OneUptime versions prior to 10.0.21
Description
OneUptime is a solution for monitoring and managing online services. A path traversal issue exists in the
/workflow/docs/:componentName API endpoint, allowing unauthenticated reading of arbitrary files from the server filesystem. The componentName route parameter is directly concatenated into a file path and passed to the res.sendFile() function within the orker/FeatureSet/Workflow/Index.ts file without any sanitization or authentication checks.Recommendations
Update to version 10.0.21 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oneuptime