Server-side Template Injection Vulnerability in Uptime Kuma Monitoring Tool
CVE-2026-33130

6.5MEDIUM

Key Information:

Vendor

Louislam

Vendor
CVE Published:
20 March 2026

What is CVE-2026-33130?

Uptime Kuma, an open source monitoring tool, is affected by a Server-side Template Injection vulnerability in versions 1.23.0 through 2.2.0. Despite attempts at mitigation in the Liquid engine, the implemented fixes only block quoted paths. This leaves systems susceptible to attacks exploiting unquoted absolute paths, allowing attackers to read sensitive files on the server. Specifically, the fix does not adequately contain the third resolution step in the LiquidJS library, exposing vulnerabilities that could lead to severe data breaches. An updated version, 2.2.1, addresses these security flaws.

Affected Version(s)

uptime-kuma >= 1.23.0, < 2.2.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.