top of page
perceptive_background_267k.jpg

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project…

Published:

9 maart 2026 om 23:00:00

Alert date:

10 maart 2026 om 19:06:17

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

OneUptime monitoring solution prior to version 10.0.21 contains a critical vulnerability that allows low-privileged authenticated users to execute arbitrary commands on the oneuptime-probe server/container. The issue stems from untrusted Synthetic Monitor code being executed in Node's vm while exposing live Playwright browser objects. Attackers can abuse Playwright APIs to spawn malicious executables, resulting in server-side remote code execution without requiring sandbox escape. The vulnerability has been patched in version 10.0.21.

Technical details

Mitigation steps:

Affected products:

OneUptime

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page