Vulnerabilities/

OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation

Severity:
Medium

Description

During the login process, the server response included a parameter called isMasterAdmin. By intercepting and modifying this parameter value from false to true, a user is able to gain access to the admin dashboard interface.

Recommendation

Update the @oneuptime/common package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@oneuptime/common
Anything's wrong? Let us know Last updated on November 27, 2025