Description
OneUptime’s GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is authorized for the target project. This allows an attacker to overwrite another project’s GitHub App installation binding.
Recommendation
Update the @oneuptime/common package to the latest compatible version. Followings are version details:
- Affected version(s): < 10.0.19
- Patched version(s): 10.0.19
References
Could your website be exposed too?
SmartScanner can check your website for OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding and gives you actionable findings to investigate.
Start a free scanRelated Issues
- OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data ex - CVE-2026-30956
- OneUptime:: node:vm sandbox escape in probe allows any project member to achieve RCE - CVE-2026-27574
- OneUpTime's Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE - CVE-2026-30887
- OneUptime has WhatsApp Resend Verification Authorization Bypass - CVE-2026-30959


