CVE-2026-30887Disclosure(hackerbay / oneuptime)

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch hackerbay oneuptime systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites. However, the system executes this untrusted user code inside the insecure Node.js vm module. By leveraging a standard prototype-chain escape (this.constructor.constructor), an attacker can bypass the sandbox, gain access to the underlying Node.js process object, and execute arbitrary system commands (RCE) on the oneuptime-probe container. Furthermore, because the probe holds database/cluster credentials in its environment variables, this directly leads to a complete cluster compromise. This vulnerability is fixed in 10.0.18.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oneuptime

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-10)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
oneuptime

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-09: 1Mentions · 2026-03-10: 2Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 103-0903-10
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-091
Disclosure1
2026-03-102
Disclosure1Patch1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30887 Remote Code Execution in OneUptime Synthetic Monitors via Node.js... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30887 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE-2026-30887 as a Remote Code Execution vulnerability in OneUptime Synthetic Monitors via Node.js and provides a link to more details, but offers no additional technical or exploit information.

    0000032
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30887: CRITICAL] Warning: Prior to version 10.0.18, OneUptime is vulnerable to RCE due to executing untrusted user code in an insecure Node.js vm module. Update now to patch this critical security ...#cve,CVE-2026-30887,#cybersecurity https://cvefind.com/CVE-2026-30887

    Post summary

    The post warns that CVE-2026-30887 allows remote code execution in OneUptime and urges users to update to version 10.0.18 to apply the patch.

    0000031
    601 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30887: OneUptime Affected by Unsandboxe... Node.js vm module strikes again - prototype pollution via `this.constructor.constructor` escalates from synthetic monit... https://zerodaysignal.com/vulnerability/CVE-2026-30887 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑30887, detailing prototype pollution in Node.js’s vm module, without referencing PoC, exploit code, or patches.

    0000057
    140 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphackerbayoneuptime---

Explore more