<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 07:53:18 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275185</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275185</link>
      <description>EUVD-2026-275185</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275185</guid>
    </item>
    <item>
      <title>fkie_cve-2026-30920</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30920</link>
      <description>&lt;p&gt;OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime&amp;#39;s GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is authorized for the target project. This allows an attacker to overwrite another project&amp;#39;s GitHub App installation binding. Related GitHub endpoints also lack effective authorization, so a valid installation ID can be used to enumerate repositories and create CodeRepository records in an arbitrary project. This vulnerability is fixed in 10.0.19.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime&amp;#39;s GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is authorized for the target project. This allows an attacker to overwrite another project&amp;#39;s GitHub App installation binding. Related GitHub endpoints also lack effective authorization, so a valid installation ID can be used to enumerate repositories and create CodeRepository records in an arbitrary project. This vulnerability is fixed in 10.0.19.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-30920</guid>
    </item>
    <item>
      <title>GHSA-656w-6f6c-m9r6 — OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-656w-6f6c-m9r6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @oneuptime/common&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OneUptime&amp;#39;s GitHub App callback trusts attacker-controlled `state` and `installation_id` values and updates `Project.gitHubAppInstallationId` with `isRoot: true` without validating that the caller is authorized for the target project. This allows an attacker to overwrite another project&amp;#39;s GitHub App installation binding.&lt;/p&gt;
&lt;p&gt;Related GitHub endpoints also lack effective authorization, so a valid installation ID can be used to enumerate repositories and create `CodeRepository` records in an arbitrary project.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The callback decodes unsigned base64 JSON from `state` and uses the embedded `projectId` directly:&lt;/p&gt;
&lt;p&gt;- https://github.com/OneUptime/oneuptime/blob/master/Common/Server/API/GitHubAPI.ts#L34-L112&lt;/p&gt;
&lt;p&gt;It then writes the supplied `installation_id` into the target project with root privileges:&lt;/p&gt;
&lt;p&gt;```ts
await ProjectService.updateOneById({
  id: new ObjectID(projectId),
  data: { gitHubAppInstallationId: installationId },
  props: { isRoot: true },
});
```&lt;/p&gt;
&lt;p&gt;The `userId` in `state` is only checked for presence, not authenticity:&lt;/p&gt;
&lt;p&gt;- https://github.com/OneUptime/oneuptime/blob/master/Common/Server/API/GitHubAPI.ts#L73-L79&lt;/p&gt;
&lt;p&gt;The install flow also generates `state` as plain base64 JSON, not a signed or session-bound token:&lt;/p&gt;
&lt;p&gt;- https://github.com/OneUptime/oneuptime/blob/master/Common/Server/API/GitHubAPI.ts#L127-L165&lt;/p&gt;
&lt;p&gt;The follow-on endpoints are also vulnerable:&lt;/p&gt;
&lt;p&gt;- Repository listing: https://github.com/OneUptime/oneuptime/blob/master/Common/Server/API/GitHubAPI.ts#L…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @oneuptime/common&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;OneUptime&amp;#39;s GitHub App callback trusts attacker-controlled `state` and `installation_id` values and updates `Project.gitHubAppInstallationId` with `isRoot: true` without validating that the caller is authorized for the target project. This allows an attacker to overwrite another project&amp;#39;s GitHub App installation binding.&lt;/p&gt;
&lt;p&gt;Related GitHub endpoints also lack effective authorization, so a valid installation ID can be used to enumerate repositories and create `CodeRepository` records in an arbitrary project.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The callback decodes unsigned base64 JSON from `state` and uses the embedded `projectId` directly:&lt;/p&gt;
&lt;p&gt;- https://github.com/OneUptime/oneuptime/blob/master/Common/Server/API/GitHubAPI.ts#L34-L112&lt;/p&gt;
&lt;p&gt;It then writes the supplied `installation_id` into the target project with root privileges:&lt;/p&gt;
&lt;p&gt;```ts
await ProjectService.updateOneById({
  id: new ObjectID(projectId),
  data: { gitHubAppInstallationId: installationId },
  props: { isRoot: true },
});
```&lt;/p&gt;
&lt;p&gt;The `userId` in `state` is only checked for presence, not authenticity:&lt;/p&gt;
&lt;p&gt;- https://github.com/OneUptime/oneuptime/blob/master/Common/Server/API/GitHubAPI.ts#L73-L79&lt;/p&gt;
&lt;p&gt;The install flow also generates `state` as plain base64 JSON, not a signed or session-bound token:&lt;/p&gt;
&lt;p&gt;- https://github.com/OneUptime/oneuptime/blob/master/Common/Server/API/GitHubAPI.ts#L127-L165&lt;/p&gt;
&lt;p&gt;The follow-on endpoints are also vulnerable:&lt;/p&gt;
&lt;p&gt;- Repository listing: https://github.com/OneUptime/oneuptime/blob/master/Common/Server/API/GitHubAPI.ts#L…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-656w-6f6c-m9r6</guid>
    </item>
  </channel>
</rss>
