Vulnerabilities/

OneUptime: Password Reset Token Logged at INFO Level

Severity:
Medium

Description

The password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to application logs (log aggregation, Docker logs, Kubernetes pod logs) can intercept reset tokens and perform account takeover on any user.

Recommendation

Update the oneuptime package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
oneuptime
Anything's wrong? Let us know Last updated on March 16, 2026