CVE-2026-33130 | louislam uptime-kuma up to 2.2.0 notification-provider.js require.resolve filename control (EUVD-2026-13670)
A vulnerability categorized as problematic has been discovered in louislam uptime-kuma up to 2.2.0. This affects the function require.resolve of the file notification-provider.js. Such manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is uniquely identified as CVE-2026-33130. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.