CVE-2026-33396

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on the Probe container/host by abusing Synthetic Monitor Playwright script execution. Synthetic monitor code is executed in VMRunner.runCodeInNodeVM with a live Playwright page object in context. The sandbox relies on a denylist of blocked properties/methods, but it is incomplete. Specifically, _browserType and launchServer are not blocked, so attacker code can traverse `page.context().browser()._browserType.launchServer(...)` and spawn arbitrary processes. Version 10.0.35 contains a patch.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hackerbay:oneuptime:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:37

Type Values Removed Values Added
Summary
  • (es) OneUptime es una plataforma de monitoreo y observabilidad de código abierto. Antes de la versión 10.0.35, un usuario autenticado con bajos privilegios (ProjectMember) puede lograr la ejecución remota de comandos en el contenedor/host de Probe abusando de la ejecución de scripts de Playwright del Monitor Sintético. El código del monitor sintético se ejecuta en VMRunner.runCodeInNodeVM con un objeto de página de Playwright en vivo en contexto. El sandbox se basa en una lista de denegación de propiedades/métodos bloqueados, pero está incompleta. Específicamente, _browserType y launchServer no están bloqueados, por lo que el código del atacante puede recorrer 'page.context().browser()._browserType.launchServer(...)' y generar procesos arbitrarios. La versión 10.0.35 contiene un parche.

26 Mar 2026, 20:40

Type Values Removed Values Added
CPE cpe:2.3:a:hackerbay:oneuptime:*:*:*:*:*:*:*:*
First Time Hackerbay oneuptime
Hackerbay
References () https://github.com/OneUptime/oneuptime/commit/e8e4ee3ff0740eb131045ab3d67453141c46178a - () https://github.com/OneUptime/oneuptime/commit/e8e4ee3ff0740eb131045ab3d67453141c46178a - Patch
References () https://github.com/OneUptime/oneuptime/security/advisories/GHSA-cqpg-phpp-9jjg - () https://github.com/OneUptime/oneuptime/security/advisories/GHSA-cqpg-phpp-9jjg - Exploit, Vendor Advisory

26 Mar 2026, 15:16

Type Values Removed Values Added
References () https://github.com/OneUptime/oneuptime/security/advisories/GHSA-cqpg-phpp-9jjg - () https://github.com/OneUptime/oneuptime/security/advisories/GHSA-cqpg-phpp-9jjg -

26 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 14:16

Updated : 2026-06-17 10:37


NVD link : CVE-2026-33396

Mitre link : CVE-2026-33396

CVE.ORG link : CVE-2026-33396


JSON object : View

Products Affected

hackerbay

  • oneuptime
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-184

Incomplete List of Disallowed Inputs

CWE-693

Protection Mechanism Failure