


Perceptive Security
SOC/SIEM Consultancy

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript codeā¦
Published:
9 maart 2026 om 23:00:00
Alert date:
10 maart 2026 om 18:06:15
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
OneUptime monitoring solution contains a critical vulnerability in versions prior to 10.0.18 that allows remote code execution through sandbox escape. The vulnerability exists in the Synthetic Monitors feature which executes untrusted JavaScript code in an insecure Node.js vm module. Attackers can exploit prototype-chain escape techniques to bypass the sandbox and execute arbitrary system commands. The vulnerability leads to complete cluster compromise as the probe container contains database and cluster credentials in environment variables. This represents a critical security flaw affecting monitoring infrastructure with severe impact potential.
Technical details
Mitigation steps:
Affected products:
OneUptime
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-30887
https://github.com/OneUptime/oneuptime/security/advisories/GHSA-h343-gg57-2q67
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
