Launch Week Day 1: Announcing Security Design Review
go

github.com/1Panel-dev/1Panel

View on go registry
35 Total advisories
35 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 6.5
Go

CVE-2024-34352

1Panel arbitrary file write vulnerability

UNKNOWN
Go

CVE-2025-66508

1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2025-66507

1Panel – CAPTCHA Bypass via Client-Controlled Flag in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2024-39911

1Panel SQL injection in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2024-2352

1Panel is vulnerable to command injection in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2024-27288

Unauthorized Console access in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2024-24768

1Panel set-cookie is missing the Secure keyword in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2023-39966

1Panel arbitrary file write vulnerability in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2023-39964

1Panel O&M management panel has a background arbitrary file reading vulnerability in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2023-39965

1Panel Arbitrary File Download vulnerability in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2023-37477

1Panel command injection vulnerability in Firewall ip functionality in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2023-36458

1Panel vulnerable to command injection when entering the container terminal in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2023-36457

1Panel vulnerable to command injection when adding container repositories in github.com/1Panel-dev/1Panel

HIGH 7.1
Go

CVE-2025-34429

1Panel contains a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality

HIGH 7.1
Go

CVE-2025-34410

1Panel contains a cross-site request forgery (CSRF) vulnerability in the Change Username functionality

MEDIUM 4.3
Go

CVE-2025-34430

1Panel contains a cross-site request forgery (CSRF) vulnerability in the panel name management functionality

MEDIUM 6.5
Go

CVE-2025-66508

1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers

UNKNOWN
Go

CVE-2025-34429

1Panel contains a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2025-34410

1Panel contains a cross-site request forgery (CSRF) vulnerability in the Change Username functionality in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2025-34430

1Panel contains a cross-site request forgery (CSRF) vulnerability in the panel name management functionality in github.com/1Panel-dev/1Panel

HIGH 7.5
Go

CVE-2025-66507

1Panel – CAPTCHA Bypass via Client-Controlled Flag

MEDIUM 6.3
Go

CVE-2024-27288

1Panel open source panel project has an unauthorized vulnerability.

MEDIUM 5.9
Go

CVE-2024-30257

1Panel's password verification is suspected to have a timing attack vulnerability

LOW 3.5
Go

CVE-2024-24768

1Panel set-cookie is missing the Secure keyword

HIGH 7.5
Go

CVE-2023-39966

1Panel arbitrary file write vulnerability

HIGH 7.5
Go

CVE-2023-39964

1Panel O&M management panel has a background arbitrary file reading vulnerability

MEDIUM 6.5
Go

CVE-2023-39965

1Panel Arbitrary File Download vulnerability

HIGH 8.8
Go

CVE-2023-37477

1Panel command injection vulnerability in Firewall ip functionality

MEDIUM 6.3
Go

CVE-2023-36458

1Panel vulnerable to command injection when entering the container terminal

MEDIUM 6.3
Go

CVE-2023-36457

1Panel vulnerable to command injection when adding container repositories

CRITICAL 9.8
Go

CVE-2024-39907

1Panel has an SQL injection issue related to the orderBy clause

UNKNOWN
Go

CVE-2024-39907

1Panel has an SQL injection issue related to the orderBy clause in github.com/1Panel-dev/1Panel

UNKNOWN
Go

CVE-2024-30257

1Panel's password verification is suspected to have a timing attack vulnerability in github.com/1Panel-dev/1Panel

MEDIUM 6.3
Go

CVE-2024-2352

1Panel is vulnerable to command injection

UNKNOWN
Go

CVE-2024-34352

Arbitrary file write in github.com/1Panel-dev/1Panel

Ready to move

Start Securing

Free, no credit card | First findings in minutes