CVE-2026-27728: OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()
An OS command injection vulnerability in NetworkPathMonitor.performTraceroute() allows any authenticated project user to execute arbitrary operating system commands on the Probe server by injecting shell metacharacters into a monitor’s destination field.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-27728 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →