Description
OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container.
The root cause is that untrusted Synthetic Monitor code is executed inside Node’s vm while live host-realm Playwright browser and page objects are exposed to it.
Recommendation
Update the @oneuptime/common package to the latest compatible version. Followings are version details:
- Affected version(s): < 10.0.21
- Patched version(s): 10.0.21
References
Could your website be exposed too?
SmartScanner can check your website for OneUptime has Synthetic Monitor RCE via exposed Playwright browser object and gives you actionable findings to investigate.
Start a free scanRelated Issues
- OneUptime: Synthetic Monitor RCE via exposed Playwright browser object - CVE-2026-30921
- OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data ex - CVE-2026-30956
- jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method - CVE-2026-25755
- OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing cre - CVE-2026-28787


