Vulnerabilities/

OneUptime:: node:vm sandbox escape in probe allows any project member to achieve RCE

Severity:
High

Description

OneUptime lets project members write custom JavaScript that runs inside monitors. The problem is it executes that code using Node.js’s built-in vm module, which Node.js itself documents as “not a security mechanism — do not use it to run untrusted code.

Recommendation

Update the @oneuptime/common package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@oneuptime/common
Anything's wrong? Let us know Last updated on February 24, 2026