Description
A security vulnerability exists in oneuptime’s local storage handling, where a regular user can escalate privileges by modifying the is_master_admin key to true. This allows unauthorized access to administrative functionalities.
Recommendation
Update the @oneuptime/model package to the latest compatible version. Followings are version details:
- Affected version(s): < 7.0.1815
- Patched version(s): 7.0.1815
References
Could your website be exposed too?
SmartScanner can check your website for OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation and gives you actionable findings to investigate.
Start a free scanRelated Issues
- OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation - CVE-2025-66028
- Cube Core is vulnerable to privilege escalation via a specially crafted request - CVE-2026-25958
- steal vulnerable to Prototype Pollution via key variable in babel.js - CVE-2022-37266
- jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext - CVE-2024-28176


