Description
An OS command injection vulnerability in NetworkPathMonitor.performTraceroute() allows any authenticated project user to execute arbitrary operating system commands on the Probe server by injecting shell metacharacters into a monitor’s destination field.
Recommendation
Update the @oneuptime/common package to the latest compatible version. Followings are version details:
- Affected version(s): < 10.0.7
- Patched version(s): 10.0.7
References
Could your website be exposed too?
SmartScanner can check your website for OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec() and gives you actionable findings to investigate.
Start a free scanRelated Issues
- OneUptime ClickHouse SQL Injection via Aggregate Query Parameters - CVE-2026-32306
- OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts - CVE-2026-48054
- Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream - CVE-2026-42037
- OneUptime has Synthetic Monitor RCE via exposed Playwright browser object - CVE-2026-30957


