


Perceptive Security
SOC/SIEM Consultancy

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project…
Published:
9 maart 2026 om 23:00:00
Alert date:
10 maart 2026 om 19:06:17
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
OneUptime monitoring solution prior to version 10.0.21 contains a critical vulnerability that allows low-privileged authenticated users to execute arbitrary commands on the oneuptime-probe server/container. The issue stems from untrusted Synthetic Monitor code being executed in Node's vm while exposing live Playwright browser objects. Attackers can abuse Playwright APIs to spawn malicious executables, resulting in server-side remote code execution without requiring sandbox escape. The vulnerability has been patched in version 10.0.21.
Technical details
Mitigation steps:
Affected products:
OneUptime
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-30957
https://github.com/OneUptime/oneuptime/releases/tag/10.0.21
https://github.com/OneUptime/oneuptime/security/advisories/GHSA-jw8q-gjvg-8w4q
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
