Vulnerabilities/

OneUptime WhatsApp Webhook Missing Signature Verification

Severity:
High

Description

The WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update events without verifying the Meta/WhatsApp X-Hub-Signature-256 HMAC signature, allowing any unauthenticated attacker to send forged webhook payloads that manipulate notification delivery status records, suppress alerts, and corrupt audit trails.

Recommendation

Update the oneuptime package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
oneuptime
Anything's wrong? Let us know Last updated on March 20, 2026