Junglewise Threat Intelligence

CVE-2023-36822: Uptime Kuma path traversal in plugin installation

CVE-2023-36822 · Severity: low · CVSS 3.1 · Published 2024-05-01

Technologies: uptime-kuma (npm). Vendors: npm, Louis Lam.

Executive brief

Uptime Kuma is a website and service monitoring application that allows users to install third-party plugins. An authenticated attacker can exploit unsanitized plugin names to perform path traversal, enabling them to delete arbitrary files from the server. This can render Uptime Kuma or the entire system unavailable and cause permanent data loss.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in the plugin installation mechanism. When installing a plugin, the application constructs a file path using a user-supplied plugin name without proper validation or sanitization. Before downloading a plugin, the code checks if the installation directory exists and removes it recursively using fs.rmSync(). An attacker can bypass directory restrictions by using path traversal sequences (e.g., "../../../") in the plugin name parameter to reference and delete files outside the intended plugins directory. Exploitation requires authentication (low privilege) and network access to the WebSocket API endpoint. A successful attack can delete critical system files, causing service disruption and data loss. The vulnerability was fixed in version 1.22.1.

Affected products

  • Louis Lam Uptime Kuma <= 1.22.0

Timeline

  • 2023-07-04: disclosed
  • 2024-05-01: advisory
  • 2023: patched: Fixed in version 1.22.1

References

Related threats