CVE-2025-65966
Summary
A low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface.
PoC
A low-permission user sends a crafted API request to the user-creation endpoint and the system creates the account successfully.
!WhatsApp Image 2025-11-23 at 14 27 32_0e0f5889
Impact
This allows attackers to create unauthorized accounts.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/OneUptime/oneuptime/security/advisories/GHSA-m449-vh5f-574g, https://nvd.nist.gov/vuln/detail/CVE-2025-65966, https://github.com/OneUptime/oneuptime/commit/07bc6d4edde7397ea6b88f889c065ec392052ab4, https://github.com/OneUptime/oneuptime
