Vulnerabilities/

OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing cre

Severity:
High

Description

The WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client and accepted back from the client request body during verification. This violates the WebAuthn specification (W3C Web Authentication Level 2, §13.4.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@oneuptime/common
Anything's wrong? Let us know Last updated on March 06, 2026