PT-2026-3400 · 1Panel · 1Panel

Loolst

·

Publicado

2026-01-18

·

Atualizado

2026-03-13

·

CVE-2026-23525

CVSS v3.1

8.4

Alta

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 1Panel versions through 1.10.33-lts 1Panel versions through 2.0.16
Description 1Panel is a web-based control panel for Linux server management. A stored Cross-Site Scripting (XSS) issue exists in the 1Panel App Store when viewing application details. Malicious scripts can execute in the context of the user’s browser, potentially compromising session data or sensitive system interfaces. The vulnerability is caused by insufficient sanitization of content rendered by the MdEditor component with the previewOnly attribute enabled. Specifically, the App Store renders application README content without proper XSS protection, allowing script execution during content rendering. Similar issues exist in system upgrade-related components. An attacker could publish a malicious application that, when loaded by users, can execute arbitrary scripts.
Recommendations Update to version 1.10.34-lts or later. Update to version 2.0.17 or later. Implement proper XSS protection and sanitization when rendering content in the MdEditor component.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23525
GHSA-MG24-6H5C-9Q42

Produtos afetados

1Panel