Uptime Kuma has an Improper URL Handling vulnerability that can be exploited through the "real-browser" feature.
By providing a URL using the file:/// protocol (e.g., file:///etc/passwd), an attacker can obtain a screenshot
of local sensitive files, because the user input is not validated by the server.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view