CVE-2025-65966
OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface. This issue has been patched in version 9.1.0.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65966.json, https://github.com/OneUptime/oneuptime/security/advisories/GHSA-m449-vh5f-574g, https://nvd.nist.gov/vuln/detail/CVE-2025-65966
