pkg:npm/@oneuptime/common
共 11 筆 CVECRITICAL6HIGH2
✅ 檢查你的版本
所有已知漏洞
- from 0, < 10.0.21
- CRITICAL9.9CVE-2026-30956OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data exposure and account takeoverfrom 0, < 10.0.21
- from 0, < 10.0.20
- CRITICAL9.9CVE-2026-30887OneUpTime's Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCEfrom 0, < 10.0.18
- CRITICAL9.9CVE-2026-27728OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()from 0, < 10.0.7
- CRITICAL9.9CVE-2026-27574OneUptime:: node:vm sandbox escape in probe allows any project member to achieve RCEfrom 0, < 10.0.0
- HIGH8.6CVE-2026-30920OneUptime has broken access control in GitHub App installation flow that allows unauthorized project bindingfrom 0, < 10.0.19
- HIGH8.2CVE-2026-28787OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replayfrom 0, <= 10.0.11
- from 0, < 10.0.21
- from 0, < 9.1.0
- from 0, < 8.0.5567