@oneuptime/common
npm6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @oneuptime/commonpage 1 of 1
- CVE-2025-65966HIGHCVSS 8.1EG 8.1✓ Fixed in 9.1.02025-11-26
OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface. This issue has been…
- CVE-2025-66028HIGHCVSS 8.2EG 8.2✓ Fixed in 8.0.55672025-11-26
OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Response Manipulation. During the login process, the server response included a param…
- CVE-2026-30920HIGHCVSS 8.6EG 8.6✓ Fixed in 10.0.192026-03-10
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: tru…
- CVE-2026-30921CRITICALCVSS 9.9EG 9.9✓ Fixed in 10.0.202026-03-10
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is executed on the oneuptime-probe service. In the…
- CVE-2026-30957CRITICALCVSS 9.9EG 9.9✓ Fixed in 10.0.212026-03-10
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container. Th…
- CVE-2026-30959MEDIUMCVSS 5.0EG 5.0✓ Fixed in 10.0.212026-03-10
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (u…
Check whether @oneuptime/common is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @oneuptime/common CVEs against the assets you own.
Start Free Scan →