Vulnerability library
Security checkNovember 27, 2025

OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpm@oneuptime/common

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

During the login process, the server response included a parameter called isMasterAdmin. By intercepting and modifying this parameter value from false to true, a user is able to gain access to the admin dashboard interface.

Recommendation

Update the @oneuptime/common package to the latest compatible version. Followings are version details:

  • Affected version(s): < 8.0.5567
  • Patched version(s): 8.0.5567

References

Could your website be exposed too?

SmartScanner can check your website for OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated November 27, 2025