PT-2025-31703 · 1Panel · 1Panel
Lizicoco
·
Published
2025-08-01
·
Updated
2025-08-02
·
CVE-2025-54424
Lizicoco
·
Published
2025-08-01
·
Updated
2025-08-02
·
CVE-2025-54424
8.1
High
Base vector | Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
1Panel versions 2.0.5 and below
Description:
1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. The HTTPS protocol used for communication between the Core and Agent endpoints has incomplete certificate verification during certificate validation, leading to unauthorized interface access. This can result in Remote Code Execution (RCE) due to the presence of numerous command execution or high-privilege interfaces within 1Panel.
Recommendations:
Update to version 2.0.6 or later.
Fix
RCE
Command Injection
Improper Certificate Validation