PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jun 30, 2026

OneUptime < 10.0.21 - Path Traversal

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-30958
7.2
CVSShigh
Exploitable remotely over the internet · no authentication required.

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server filesystem. The componentName route parameter is concatenated directly into a file path passed to res.sendFile() in orker/FeatureSet/Workflow/Index.ts with no sanitization or authentication middleware. This vulnerability is fixed in 10.0.21.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
oneuptimeby OneUptime
< 10.0.21
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.