VYPR
High severity7.2NVD Advisory· Published Mar 10, 2026· Updated Jun 17, 2026

CVE-2026-30958

CVE-2026-30958

Description

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server filesystem. The componentName route parameter is concatenated directly into a file path passed to res.sendFile() in orker/FeatureSet/Workflow/Index.ts with no sanitization or authentication middleware. This vulnerability is fixed in 10.0.21.

Affected products

3
  • cpe:2.3:a:hackerbay:oneuptime:*:*:*:*:*:*:*:*
    Range: <10.0.21
  • Oneuptime/Oneuptimellm-fuzzy2 versions
    <10.0.21+ 1 more
    • (no CPE)range: <10.0.21
    • (no CPE)range: < 10.0.21

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.