CVE-2026-27574 is a remote code execution vulnerability in OneUptime’s custom JavaScript monitor feature. In OneUptime versions 9.5.13 and below, user-supplied JavaScript for monitors is executed using Node.js’s built-in node:vm module as a sandbox boundary. Because node:vm is not a secure isolation mechanism for untrusted code, an attacker can use a trivial, well-known sandbox escape technique based on constructor-chain access to reach the Node.js process object and then child_process, escaping the intended execution context. The vulnerable design allows low-privilege users to supply code that is executed by the probe process. The issue is especially severe because monitor creation is available to the ProjectMember role, and open registration is enabled by default, making exploitation reachable by anonymous internet users in default deployments. The probe process also runs with host networking and stores sensitive cluster credentials in environment variables, including ONEUPTIME_SECRET, DATABASE_PASSWORD, REDIS_PASSWORD, and CLICKHOUSE_PASSWORD. The issue is fixed in version 10.0.5.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python PoC exploit script and a README. The exploit targets CVE-2026-27574 in OneUptime versions < 10.0.0, abusing the Custom JavaScript Monitor feature to inject attacker-controlled JavaScript that executes in the probe/worker context. The injected JS uses a constructor-chain escape (`this.constructor.constructor`) to obtain Node.js `process`, then loads `child_process` to execute system commands and read sensitive environment variables. The Python script automates the full attack chain over HTTP: (1) registers a new account via `POST /api/accounts/register` (assumes open registration), (2) creates a project via `POST /api/project`, (3) creates a malicious monitor via `POST /api/monitor` with `type: javascript-monitor` and `customCode` set to the payload, (4) waits ~90 seconds for the probe to run (monitor interval 60s), then (5) fetches status and logs via `GET /api/monitor/{id}/status` and `GET /api/monitor/{id}/logs` to print leaked data. A reverse shell payload is included but commented out; enabling it would require editing MALICIOUS_CODE (the provided CLI lhost/lport are otherwise unused by default). Overall purpose: demonstrate authenticated-but-low-privilege RCE and secret leakage in vulnerable OneUptime deployments; fix noted as OneUptime 10.0.0 (move to isolated-vm).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.