CVE-2026-30957Critical· 9.9▾ MidnightOneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container. …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.1%
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container. The root cause is that untrusted Synthetic Monitor code is executed inside Node's vm while live host-realm Playwright browser and page objects are exposed to it. A malicious user can call Playwright APIs on the injected browser object and cause the probe to spawn an attacker-controlled executable. This is a server-side remote code execution issue. It does not require a separate vm sandbox escape. This vulnerability is fixed in 10.0.21.
oneuptime < 10.0.21Upgrade past the affected range:
oneuptime 10.0.21Connected by shared product, vendor, weakness, or advisory.
CVE-2026-30958High· 7.2OneUptime is a solution for monitoring and managing online services
CVE-2026-30959Medium· 5.0OneUptime is a solution for monitoring and managing online services
CVE-2026-30956Critical· 9.9OneUptime is a solution for monitoring and managing online services
CVE-2026-33396Critical· 9.9OneUptime is an open-source monitoring and observability platform
CVE-2026-33142High· 8.1OneUptime is a solution for monitoring and managing online services
CVE-2026-33143High· 7.5OneUptime is a solution for monitoring and managing online services