Miggo Logo

GHSA-vffh-c9pq-4crh: Uptime Kuma Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File Read

6.5

CVSS Score
3.1

Basic Information

CVE ID
-
EPSS Score
-
Published
10/20/2025
Updated
10/20/2025
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
uptime-kumanpm= 2.0.0-dev.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Summ*ry In som* Noti*i**tion typ*s (*.*., W***ook, T*l**r*m), t** `s*n*()` *un*tion *llows us*r-*ontroll** r*n**rT*mpl*t* input. T*is l***s to * S*rv*r-si** T*mpl*t* Inj**tion (SSTI) vuln*r**ility t**t **n ** *xploit** to r*** *r*itr*ry *il*s *r

Reasoning

No *n*lysis *v*il**l*
GHSA-vffh-c9pq-4crh: Uptime Kuma Notification SSTI | Miggo