PT-2026-24254 · Oneuptime · Oneuptime

Iconnnjka

·

Published

2026-03-10

·

Updated

2026-03-17

·

CVE-2026-30958

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OneUptime versions prior to 10.0.21
Description OneUptime is a solution for monitoring and managing online services. A path traversal issue exists in the /workflow/docs/:componentName API endpoint, allowing unauthenticated reading of arbitrary files from the server filesystem. The componentName route parameter is directly concatenated into a file path and passed to the res.sendFile() function within the orker/FeatureSet/Workflow/Index.ts file without any sanitization or authentication checks.
Recommendations Update to version 10.0.21 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30958
GHSA-P2WH-9PW8-HVFF

Affected Products

Oneuptime