# uptime kuma 2.5.4

Published articles for uptime kuma 2.5.4.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Uptime Kuma 2.5.4 Patches Critical JSONata Code Execution Flaw

DevFeed: [Uptime Kuma 2.5.4 Patches Critical JSONata Code Execution Flaw](<https://devfeed.tech/articles/uptime-kuma-2-5-4-patches-critical-jsonata-code-execution-flaw-17352.md>)

Original publisher: [Read original article](<https://selfhostlab.io/uptime-kuma-2-5-4-security-release/>)

Author: Christian Rakoot

Published: 2026-09-14T06:55:25Z

Content type: article

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [monitoring-news](<https://devfeed.tech/tags/monitoring-news.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>), [update](<https://devfeed.tech/tags/update.md>), [uptime-kuma-2-5-4](<https://devfeed.tech/tags/uptime-kuma-2-5-4.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Uptime Kuma 2.5.4 fixes a critical JSONata vulnerability that could enable arbitrary code execution on the monitor host, along with a second denial-of-service issue. The release updates jsonata to 2.2.2 and also adds an SFTP monitor type and three notification providers.

### Source excerpt

Uptime Kuma 2.5.4 patches a critical-rated code execution flaw in the JSONata library (CVE-2026-77415, CVSS 9.3) plus a second denial-of-service fix, and adds an SFTP monitor type and three new notification providers. Here's what the flaw actually requires to exploit, and how to update.