OneUptime: Synthetic Monitor RCE via exposed Playwright browser object
Modified: 3/10/2026
package
pkg:npm/%40oneuptime/common
OneUptime: Synthetic Monitor RCE via exposed Playwright browser object
Modified: 3/10/2026
OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding
Modified: 3/10/2026
OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation
Modified: 11/27/2025
OneUptime has WhatsApp Resend Verification Authorization Bypass
Modified: 3/10/2026
OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay
Modified: 3/6/2026
OneUpTime's Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE
Modified: 3/10/2026
OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()
Modified: 2/28/2026
OneUptime has Synthetic Monitor RCE via exposed Playwright browser object
Modified: 3/10/2026
OneUptime Unauthorized User Creation via API
Modified: 12/1/2025
OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data exposure and account takeover
Modified: 3/10/2026
OneUptime:: node:vm sandbox escape in probe allows any project member to achieve RCE
Modified: 2/24/2026