Description
The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the verify endpoint).
Recommendation
Update the @oneuptime/common package to the latest compatible version. Followings are version details:
- Affected version(s): < 10.0.21
- Patched version(s): 10.0.21
References
- GHSA-cw6x-mw64-q6pv
- CVE-2026-30959
- CWE-285
- CWE-307
- CWE-639
- CWE-862
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A6
- OWASP 2021-A7
Related Issues
- OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data ex - CVE-2026-30956
- OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing cre - CVE-2026-28787
- Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix - CVE-2026-44489
- Clerk has an authorization bypass when combining organization, billing, or reverification checks - CVE-2026-42349
You might also like:
- Tags:
- npm
- @oneuptime/common
Anything's wrong? Let us know Last updated on March 10, 2026


