OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server filesystem. The componentName route parameter is concatenated directly into a file path passed to res.sendFile() in orker/FeatureSet/Workflow/Index.ts with no sanitization or authentication middleware. This vulnerability is fixed in 10.0.21.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oneuptime
Oneuptime oneuptime |
|
| Vendors & Products |
Oneuptime
Oneuptime oneuptime |
Tue, 10 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server filesystem. The componentName route parameter is concatenated directly into a file path passed to res.sendFile() in orker/FeatureSet/Workflow/Index.ts with no sanitization or authentication middleware. This vulnerability is fixed in 10.0.21. | |
| Title | OneUptime: Path Traversal — Arbitrary File Read (No Auth) | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-10T17:01:43.524Z
Updated: 2026-03-10T17:31:08.598Z
Reserved: 2026-03-07T17:34:39.981Z
Link: CVE-2026-30958
Updated: 2026-03-10T17:30:53.138Z
Status : Awaiting Analysis
Published: 2026-03-10T18:18:54.883
Modified: 2026-03-11T13:53:20.707
Link: CVE-2026-30958
No data.
ReportizFlow