OneUptime Synthetic Monitors Playwright Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in OneUptime versions prior to 10.0.20. The issue arises in Synthetic Monitors, where low-privileged project users can submit custom Playwright scripts that are executed on the oneuptime-probe service. This untrusted code runs inside Node's virtual machine and has access to live Playwright objects, such as browser and page. Exploiting this vulnerability allows an attacker to use the Playwright browser object to launch arbitrary executables on the probe host or container, creating a significant security risk.

Impact

Exploitation of this vulnerability allows for remote code execution on the probe host or container.

Reproduction

To reproduce this vulnerability, log in as a user with normal project membership and navigate to 'Monitors -> Create New Monitor'. Select 'Synthetic Monitor' and paste a malicious Playwright script into the 'Playwright Code' section. Choose a browser type and screen size, set the retry count to 0, and click 'Test Monitor'. The injected code will be executed, and the output will be displayed, demonstrating successful exploitation.

Remediation

Users are advised to update to OneUptime version 10.0.20 or later.

Added: Mar 10, 2026, 5:55 PM
Updated: Mar 10, 2026, 5:55 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.6
remediation
0.0
relevance
3.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.