Vulnerabilities/

OneUptime has WhatsApp Resend Verification Authorization Bypass

Severity:
Medium

Description

The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the verify endpoint).

Recommendation

Update the @oneuptime/common package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@oneuptime/common
Anything's wrong? Let us know Last updated on March 10, 2026