-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| uptime-kuma | npm | >= 1.23.0, <= 2.0.0-dev.0 |
The vulnerability stems from insecure regex patterns in URL sanitization logic. Both functions construct notification URLs using replace() with patterns that: