Executive brief
OneUpTime is an open-source monitoring platform that allows project members to write custom JavaScript/Playwright code within Synthetic Monitors to test websites. A critical sandbox escape vulnerability in the Node.js vm module execution allows any project member to bypass the sandbox, execute arbitrary system commands on the probe container, and access sensitive environment variables containing database credentials, resulting in complete cluster compromise.
Technical details
The vulnerability exists in Common/Server/Utils/VM/VMRunner.ts where user-supplied JavaScript is executed using vm.runInContext() without any AST filtering or secure isolation. An attacker with Project Member privileges can use a prototype-chain escape payload (this.constructor.constructor('return process')()) to bypass the sandbox, gain access to the underlying Node.js process object, and execute arbitrary shell commands via the child_process module. Since the oneuptime-probe service runs with access to sensitive environment variables (ONEUPTIME_SECRET, DATABASE_PASSWORD, etc.), attackers can trivially exfiltrate cluster secrets. The vulnerability is exploitable through the OneUpTime web dashboard GUI, and since open registration is enabled by default, unauthenticated external attackers can create an account and instantly compromise deployments. Patch: version 10.0.18 and later.
Affected products
- OneUpTime OneUpTime < 10.0.18
Timeline
- 2026-03-07: disclosed
- 2026-03-07: patched: version 10.0.18