Junglewise Threat Intelligence

Uptime Kuma Server-side Template Injection in notification templates

Severity: low · CVSS 3.1 · Published 2025-10-20

Technologies: uptime-kuma (npm). Vendors: npm, Louis Lam.

Executive brief

Uptime Kuma is a self-hosted monitoring tool used to track the availability of websites and services. A Server-side Template Injection vulnerability in notification templates allows authenticated users to read arbitrary files from the server, potentially exposing sensitive configuration files, secrets, or data stored on the system.

Technical details

The vulnerability is a Server-side Template Injection (SSTI) in Uptime Kuma's renderTemplate() function, which instantiates a Liquid template engine and processes user-controlled input without sanitization or sandboxing. In notification types such as Webhook and Telegram, user-editable fields are passed directly to renderTemplate(), allowing attackers to inject malicious Liquid template syntax (e.g., {% render '/etc/passwd' %}). An authenticated user with notification configuration permissions can craft a custom webhook body containing template injection payloads to read arbitrary files from the server. The attack requires authentication but no further user interaction. Patches are available in versions 1.23.17 and 2.0.0.

Affected products

  • Louis Lam Uptime Kuma 1.23.0 through 1.23.16, 2.0.0-beta.4 and earlier

Timeline

  • 2025-10-20: disclosed
  • 2025-10-20: patched: Patched in versions 1.23.17 and 2.0.0

References

Related threats