PT-2025-31703 · 1Panel · 1Panel

Lizicoco

·

Published

2025-08-01

·

Updated

2025-08-26

·

CVE-2025-54424

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 1Panel versions 2.0.5 and below
Description 1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. The HTTPS protocol used for communication between the Core and Agent endpoints has incomplete certificate verification during certificate validation, leading to unauthorized interface access. This can result in Remote Code Execution (RCE) due to the presence of numerous command execution or high-privilege interfaces within 1Panel.
Recommendations Update to version 2.0.6 or later.

Exploit

Fix

RCE

Improper Certificate Validation

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-54424
GHSA-8J63-96WH-WH3J
GO-2025-3834
OPENSUSE-SU-2025:15434-1
SUSE-SU-2025:02912-1

Affected Products

1Panel