Junglewise Threat Intelligence

Uptime Kuma authenticated remote code execution via TailscalePing

Severity: info · Published 2023-11-27

Technologies: uptime-kuma (npm). Vendors: npm, Louis Lam.

Executive brief

Uptime Kuma is a self-hosted monitoring tool that allows users to add monitors to track system availability. An authenticated attacker can inject arbitrary shell commands into the TailscalePing monitor's hostname field, enabling remote code execution on the server. While authentication is required, the vulnerability can be exploited by removing client-side input validation, allowing an attacker with legitimate access to compromise the entire server and execute arbitrary commands.

Technical details

The vulnerability is an OS command injection (CWE-78) in the TailscalePing monitor class. The runTailscalePing method constructs a shell command by directly interpolating the user-supplied hostname parameter into a command string without sanitization: `let cmd = \`tailscale ping ${hostname}\``. The command is then executed via Node.js exec(), which invokes a shell and interprets shell metacharacters. An authenticated attacker can bypass the frontend pattern validation by modifying the DOM or intercepting WebSocket messages (and may also need to disable container detection), then inject a payload like `$(id >&2)` to execute arbitrary commands with the privileges of the Uptime Kuma process. The issue was fixed in version 1.23.7 by switching to the spawn() method with array-based arguments, which does not interpret shell syntax.

Affected products

  • Louis Lam Uptime Kuma 1.23.0 through 1.23.6

Timeline

  • 2023-11-24: disclosed
  • 2023-11-27: patched: fixed in version 1.23.7

References

Related threats