OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation
- Severity:
- High
Description
A security vulnerability exists in oneuptime’s local storage handling, where a regular user can escalate privileges by modifying the is_master_admin key to true. This allows unauthorized access to administrative functionalities.
Recommendation
Update the @oneuptime/model package to the latest compatible version. Followings are version details:
- Affected version(s): < 7.0.1815
- Patched version(s): 7.0.1815
References
Related Issues
- OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation - CVE-2025-66028
- Cube Core is vulnerable to privilege escalation via a specially crafted request - CVE-2026-25958
- steal vulnerable to Prototype Pollution via key variable in babel.js - CVE-2022-37266
- jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext - CVE-2024-28176
You might also like:
- Tags:
- npm
- @oneuptime/model
Anything's wrong? Let us know Last updated on March 26, 2024


