CVE-2026-30957 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-30957 requires immediate attention.

· 3 min read

```html

Executive Summary

A critical vulnerability, CVE-2026-30957, has been identified in the npm package @oneuptime/common. This issue allows low-privileged authenticated users to execute arbitrary commands on the server, leading to potential Remote Code Execution (RCE). If your application uses this package, immediate action is required to mitigate risks.

Immediate Action

  • Immediately review your project for the use of @oneuptime/common.
  • Restrict access to the OneUptime dashboard for non-administrative users.
  • Upgrade to the latest secure version of @oneuptime/common as soon as it is released.
  • Consider isolating the affected service from critical internal resources to limit potential damage.
  • Monitor for unusual activity in your environment that may indicate exploitation attempts.
  • Stay tuned for updates from OneUptime regarding a patch release.

Affected Versions

  • @oneuptime/common@<1.2.4 vulnerable; upgrade to @oneuptime/common@1.2.4+

Resolution Guide

To upgrade to a secure version of the package, run the following command:

npm install @oneuptime/common@1.2.4

Ensure you review your project’s access control measures and restrict the creation and execution of Synthetic Monitors to trusted users only.

Detection & Verification

To check if you are using a vulnerable version, run:

npm list @oneuptime/common

Verify the fix by ensuring that the installed version is 1.2.4 or higher. You can also use dependency auditing tools to check for vulnerabilities:

npm audit

Risk and Impact

This vulnerability poses a severe risk, as it allows attackers with basic project access to execute arbitrary commands on your server. The impact is particularly critical in environments where the probe has access to sensitive internal services, secrets, and credentials, potentially leading to a full compromise of your infrastructure.

```

Keep reading