CVE-2026-30958
EUVD-2026-1056310.03.2026, 18:18
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server filesystem. The componentName route parameter is concatenated directly into a file path passed to res.sendFile() in orker/FeatureSet/Workflow/Index.ts with no sanitization or authentication middleware. This vulnerability is fixed in 10.0.21.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hackerbay | oneuptime | 𝑥 < 10.0.21 |
𝑥
= Vulnerable software versions